Weaknesses of type CWE-295

853 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2024-25141CRITICALApache Airflow Mongo Provider: Certificate validation isn't respected even if SSL is enabled for apache-airflow-providers-mongoEPSS 0.6%CVE-2024-13990CRITICALMicroWorld eScan AV Insecure Update Mechanism Allows Man-in-the-Middle Replacement of UpdatesEPSS 0.6%CVE-2012-0955MEDIUMsoftware-properties incorrectly validated TLS certificatesEPSS 0.6%CVE-2014-8164—A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red EPSS 0.6%CVE-2026-27137HIGHIncorrect enforcement of email constraints in crypto/x509EPSS 0.6%CVE-2020-5367HIGHDell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, anEPSS 0.6%CVE-2023-23131HIGHSelfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.EPSS 0.6%CVE-2019-0054MEDIUMJunos OS: SRX Series: An attacker may be able to perform Man-in-the-Middle (MitM) attacks during app-id signature updates.EPSS 0.6%CVE-2023-41180—Apache NiFi MiNiFi C++: Incorrect Certificate Validation in InvokeHTTP for MiNiFi C++EPSS 0.6%CVE-2024-31872HIGHIBM Security Verify Access Appliance missing certificate validationEPSS 0.6%CVE-2024-31871HIGHIBM Security Verify Access Appliance improper certificate validationEPSS 0.6%CVE-2024-7570HIGHImproper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM pEPSS 0.6%CVE-2022-24319—A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the cEPSS 0.6%CVE-2023-51634HIGHNETGEAR RAX30 Improper Certificate Validation Remote Code Execution VulnerabilityEPSS 0.6%CVE-2021-46880CRITICALx509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverifEPSS 0.6%CVE-2026-80230HIGHOpenSSL pinning bypassEPSS 0.6%CVE-2021-3460HIGHThe Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the supportEPSS 0.6%CVE-2026-8992HIGHAn improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to exEPSS 0.6%CVE-2023-23546MEDIUMA misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middlEPSS 0.6%CVE-2023-43017HIGHIBM Security Verify Access man in the middleEPSS 0.6%