Fallos del tipo CWE-295

854 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-50302MEDIUMWindows Cryptographic Services Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2024-29171MEDIUMDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote EPSS 0.3%CVE-2024-27323HIGHPDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-32293MEDIUMGL-iNet Comet (GL-RM1) KVM insufficient certificate validationEPSS 0.3%CVE-2026-42789HIGHNon-CA certificate accepted as intermediate issuer in public_key path validationEPSS 0.3%CVE-2026-6450LOWCRL critical extension bypass in ParseCRL_ExtensionsEPSS 0.3%CVE-2026-85102CRITICALImproper Certificate Validation in Quantum Security GatewayEPSS 0.3%KEVCVE-2020-25680A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknowEPSS 0.3%CVE-2025-44018HIGHA firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can leaEPSS 0.3%CVE-2023-31421MEDIUMBeats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issueEPSS 0.3%CVE-2023-30517MEDIUMJenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when coEPSS 0.3%CVE-2024-43177MEDIUMIBM Concert improper certificate validationEPSS 0.3%CVE-2026-46428CRITICALlettre has TLS hostname verification disabled when using Boring TLS backendEPSS 0.3%CVE-2026-66795CRITICALManagedcluster-import-controller: csr auto-approver does not validate certificate subject or signername (spoke→hub cluster-admin)EPSS 0.3%CVE-2025-20670MEDIUMIn Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, ifEPSS 0.3%CVE-2023-1514HIGHA vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certEPSS 0.3%CVE-2026-25644HIGHDataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgradeEPSS 0.3%CVE-2026-42791MEDIUMOCSP responder certificate validity period not checked in public_keyEPSS 0.3%CVE-2018-19946MEDIUMThe vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerabilitEPSS 0.3%CVE-2021-32755MEDIUMCertificate pinning is not enforced on the web socket connectionEPSS 0.3%