Fallos del tipo CWE-295

853 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2024-28161MEDIUMIn Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control TowEPSS 0.4%CVE-2021-1354MEDIUMCisco Unified Computing System Central Software Improper Certificate Validation VulnerabilityEPSS 0.4%CVE-2022-1632An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the defEPSS 0.4%CVE-2025-32878CRITICALAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is EPSS 0.4%CVE-2021-22511Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affectsEPSS 0.4%CVE-2024-43201HIGHPlanet Fitness Workouts mobile apps do not properly validate TLS certificatesEPSS 0.4%CVE-2026-42769MEDIUMTrust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdateEPSS 0.4%CVE-2021-1277HIGHCisco Data Center Network Manager Certificate Validation VulnerabilitiesEPSS 0.4%CVE-2021-1276HIGHCisco Data Center Network Manager Certificate Validation VulnerabilitiesEPSS 0.4%CVE-2021-23167HIGHImproper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the CommEPSS 0.4%CVE-2024-8007HIGHOpenstack-tripleo-common: rhosp director disables tls verification for registry mirrorsEPSS 0.4%CVE-2024-42395CRITICALUnauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the AP Certificate Management Service Accessed by the PAPI ProtocolEPSS 0.4%CVE-2025-1014HIGHCertificate length was not properly checkedEPSS 0.4%CVE-2024-45159CRITICALAn issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the clieEPSS 0.4%CVE-2024-7383HIGHLibnbd: nbd server improper certificate validationEPSS 0.4%CVE-2025-1193HIGHImproper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows aEPSS 0.4%CVE-2023-29000MEDIUMNextcloud Desktop client does not verify received singed certificate in end-to-end encryptionEPSS 0.4%CVE-2022-34394LOWDell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unauthenticated attacker EPSS 0.4%CVE-2026-13410HIGHDancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabledEPSS 0.4%CVE-2023-48427HIGHA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificEPSS 0.4%