Fallos del tipo CWE-295

854 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2025-66001HIGHNeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)EPSS 0.4%CVE-2024-31489MEDIUMAAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinEPSS 0.4%CVE-2026-11564CRITICALNative CA trust persistEPSS 0.4%CVE-2025-4575MEDIUMThe x509 application adds trusted use instead of rejected useEPSS 0.4%CVE-2022-39161MEDIUMIBM WebSphere Application Server information disclosureEPSS 0.4%CVE-2022-48437MEDIUMAn issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain doesEPSS 0.4%CVE-2023-20881HIGHCloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drainEPSS 0.4%CVE-2023-31190HIGHMissing TLS (HTTPS) certificate validation during firmware update in DroneScout ds230 Remote ID receiver from BlueMark InnovationsEPSS 0.4%CVE-2025-65753HIGHAn issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.EPSS 0.4%CVE-2024-48460MEDIUMAn issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and passEPSS 0.4%CVE-2025-30024MEDIUMThe communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.EPSS 0.4%CVE-2024-40714HIGHAn improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitiveEPSS 0.4%CVE-2025-36041MEDIUMIBM MQ improper certificate validationEPSS 0.4%CVE-2026-32794MEDIUMApache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token ExchangeEPSS 0.4%CVE-2026-42012HIGHGnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sansEPSS 0.4%CVE-2024-47619HIGHtranport: TLS host name wildcard matching too laxEPSS 0.4%CVE-2024-4062LOWHualai Xiaofang iSC5 certificate validationEPSS 0.4%CVE-2022-45457MEDIUMSensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis AgeEPSS 0.4%CVE-2025-55109CRITICALBMC Control-M/Agent default SSL/TLS configuration authenticated bypassEPSS 0.4%CVE-2022-45458MEDIUMSensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis AgeEPSS 0.4%