Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2024-31955MEDIUMAn issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows EPSS 0.2%CVE-2026-6860MEDIUMA TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard nameEPSS 0.2%CVE-2024-6472HIGHAbility to trust not validated macro signatures removed in high security modeEPSS 0.2%CVE-2023-33861MEDIUMIBM Security ReaQta improper certificate validationEPSS 0.2%CVE-2024-7206HIGHFirmware extraction and Hardware SSL Pinning BypassEPSS 0.2%CVE-2023-6055HIGHImproper Certificate Validation in Bitdefender Total Security HTTPS Scanning (VA-11158)EPSS 0.2%CVE-2026-15554HIGHUndertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgeryEPSS 0.2%CVE-2025-7395CRITICALDomain Name Validation Bypass with Apple Native Certificate ValidationEPSS 0.2%CVE-2026-61668HIGHDIRAC: Pilot code downloaded over unverified HTTPS connectionEPSS 0.2%CVE-2026-11310HIGHX.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoringEPSS 0.2%CVE-2025-30277HIGHQsync CentralEPSS 0.2%CVE-2025-30278HIGHQsync CentralEPSS 0.2%CVE-2026-15078HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2026-11999HIGHX.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()EPSS 0.2%CVE-2026-55960HIGHUn-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validationEPSS 0.2%CVE-2025-9293HIGHInsufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle InterceptionEPSS 0.2%CVE-2024-11621HIGHMissing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modifEPSS 0.2%CVE-2025-67752HIGHOpenEMR Has Disabled SSL Certificate Verification in HTTP ClientEPSS 0.2%CVE-2024-33612MEDIUMBIG-IP Next Central Manager vulnerabilityEPSS 0.2%CVE-2025-59353HIGHManager generates mTLS certificates for arbitrary IP addressesEPSS 0.2%