Weaknesses of type CWE-295

869 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2025-44964LOWA lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive informaEPSS 0.1%CVE-2025-20215MEDIUMCisco Webex Meeting Client Join Certificate Validation VulnerabilityEPSS 0.1%CVE-2026-41012HIGHBOSH vSphere CPI Improper Cert ValidationEPSS 0.1%CVE-2025-30669MEDIUMZoom Workplace Clients - Improper Certificate ValidationEPSS 0.1%CVE-2024-38642LOWQuMagieEPSS 0.1%CVE-2026-20500MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution EPSS 0.1%CVE-2025-12893LOWImproper Certificate Validation May Allow Successful TLS Handshaking Despite Invalid Extended Key Usage Fields in MongoDB ServerEPSS 0.1%CVE-2025-6026LOWAn improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable ofEPSS 0.1%CVE-2026-46734HIGHDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low priviEPSS 0.1%CVE-2026-20323HIGHCisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass VulnerabilityEPSS 0.1%CVE-2026-79975MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2026-0392HIGHeParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-updateEPSS 0.1%CVE-2026-73587MEDIUMDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. AEPSS 0.1%CVE-2025-32745MEDIUMDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adEPSS 0.1%CVE-2026-91812HIGHFoxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation VulnerabilityEPSS 0.1%CVE-2024-42186LOWHCL BigFix Patch Download Plug-ins are affected by an insecure protocol supportEPSS 0.1%CVE-2026-1068MEDIUMAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2023-21358HIGHIn UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypEPSS 0.1%CVE-2024-14024LOWVideo StationEPSS 0.1%CVE-2026-12374MEDIUMImproper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperToolEPSS 0.1%