Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2024-10444HIGHImproper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-EPSS 0.3%CVE-2025-54809HIGHF5 Access for Android vulnerabilityEPSS 0.3%CVE-2026-17024HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2024-28067MEDIUMA vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode of packets going to tEPSS 0.3%CVE-2025-3218MEDIUMIBM i improper certificate validationEPSS 0.3%CVE-2025-6037MEDIUMVault Certificate Auth Method Did Not Validate Common Name For Non-CA CertificatesEPSS 0.2%CVE-2026-34580CRITICALBotan has a certificate authentication bypass due to trust anchor confusionEPSS 0.2%CVE-2023-32464LOW Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potEPSS 0.2%CVE-2025-7095MEDIUMComodo Internet Security Premium Update certificate validationEPSS 0.2%CVE-2024-23928MEDIUMPioneer DMH-WT7600NEX Telematics Improper Certificate ValidationEPSS 0.2%CVE-2023-31151MEDIUMImproper Certificate ValidationEPSS 0.2%CVE-2023-47742MEDIUMIBM QRadar Suite information dislosureEPSS 0.2%CVE-2025-46788HIGHZoom Workplace for Linux - Improper Certificate ValidationEPSS 0.2%CVE-2026-25160CRITICALAlist has Insecure TLS ConfigEPSS 0.2%CVE-2023-32994LOWJenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOraEPSS 0.2%CVE-2022-22380MEDIUMIBM Security Verify Privilege improper authenticationEPSS 0.2%CVE-2026-52724MEDIUMkuma-dp connects to control plane without verifying TLS certificate when no CA is configuredEPSS 0.2%CVE-2025-11619HIGHImproper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to EPSS 0.2%CVE-2026-71290CRITICALApache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)EPSS 0.2%CVE-2025-13034MEDIUMNo QUIC certificate pinning with GnuTLSEPSS 0.2%