Fallos del tipo CWE-295

853 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-4370CRITICALImproper TLS Client/Server authentication and certificate verification on Database ClusterEPSS 0.4%CVE-2022-1834MEDIUMWhen displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird EPSS 0.4%CVE-2023-6680HIGHImproper Certificate Validation in GitLabEPSS 0.4%CVE-2024-52329CRITICALECOVACS HOME mobile app plugins do not properly validate TLS certificatesEPSS 0.4%CVE-2024-41334HIGHDraytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior EPSS 0.4%CVE-2022-31733CRITICALStarting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another EPSS 0.4%CVE-2025-10548MEDIUMMissing Certificate Validation in CleverControl Installer Allows Remote Code ExecutionEPSS 0.4%CVE-2023-5594HIGHImproper following of a certificate's chain of trust in ESET security productsEPSS 0.4%CVE-2022-1197MEDIUMWhen importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the keyEPSS 0.4%CVE-2022-40147A vulnerability has been identified in Industrial Edge Management (All versions < V1.5.1). The affected software does not properly validate EPSS 0.4%CVE-2025-24471MEDIUMAn Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP veriEPSS 0.4%CVE-2026-27134HIGHStrimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autenticationEPSS 0.4%CVE-2023-0430MEDIUMCertificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayEPSS 0.4%CVE-2023-0547MEDIUMOCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be acceEPSS 0.4%CVE-2024-54849MEDIUMAn issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a EPSS 0.4%CVE-2024-10445MEDIUMImproper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskEPSS 0.4%CVE-2022-45419MEDIUMIf the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certifiEPSS 0.4%CVE-2024-48915HIGHAgent Dart missing certificate verification checksEPSS 0.4%CVE-2026-65084HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation.EPSS 0.4%CVE-2025-66001HIGHNeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)EPSS 0.4%