Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2024-28021HIGHA vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an aEPSS 0.3%CVE-2026-41016MEDIUMApache Airflow Providers SMTP: No certificate validation on SMTP STARTTLS connections in SMTP providerEPSS 0.3%CVE-2025-65830CRITICALDue to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstEPSS 0.3%CVE-2023-50315MEDIUMIBM WebSphere Application Server information disclosureEPSS 0.3%CVE-2026-76242CRITICALstigmem Federation Peer Registration Authentication BypassEPSS 0.3%CVE-2026-9258HIGHImproper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.3%CVE-2024-47119MEDIUMIBM Storage Defender - Resiliency Service improper certificate validationEPSS 0.3%CVE-2026-67294CRITICALFreeRDP before 3.29.0 TLS Certificate EKU BypassEPSS 0.3%CVE-2025-50944HIGHAn issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X5EPSS 0.3%CVE-2023-38686CRITICALSydent does not verify email server certificatesEPSS 0.3%CVE-2026-1530HIGHFog-kubevirt: fog-kubevirt: man-in-the-middle vulnerability due to disabled certificate validationEPSS 0.3%CVE-2026-90623MEDIUMandreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validationEPSS 0.3%CVE-2026-54919HIGHcpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backendsEPSS 0.3%CVE-2025-30279HIGHFile Station 5EPSS 0.3%CVE-2025-29884HIGHFile Station 5EPSS 0.3%CVE-2025-33031HIGHFile Station 5EPSS 0.3%CVE-2025-22486HIGHFile Station 5EPSS 0.3%CVE-2025-29885HIGHFile Station 5EPSS 0.3%CVE-2025-40801CRITICALA vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional TranslaEPSS 0.3%CVE-2025-29883HIGHFile Station 5EPSS 0.3%