Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2025-11043CRITICALImproper Server Certificate Validation in Automation StudioEPSS 0.2%CVE-2025-56231CRITICALTonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass updaEPSS 0.2%CVE-2022-45856MEDIUMAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 aEPSS 0.2%CVE-2024-37311HIGHCollabora Online's remote host TLS certificates are not fully verifiedEPSS 0.2%CVE-2026-63650LOWOpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 usernaEPSS 0.2%CVE-2024-50691HIGHSunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certifEPSS 0.2%CVE-2026-47074HIGHex_aws_sns SigningCertURL not validated in verify_message/1EPSS 0.2%CVE-2025-0239MEDIUMAlt-Svc ALPN validation failure when redirectedEPSS 0.2%CVE-2024-23970MEDIUMChargePoint Home Flex Improper Certificate ValidationEPSS 0.2%CVE-2026-58162HIGHApache Traffic Server: Certifier plugin trusts client SNI when generating certificatesEPSS 0.2%CVE-2026-45388CRITICALIn OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersEPSS 0.2%CVE-2024-27440MEDIUMThe Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly veEPSS 0.2%CVE-2026-6900CRITICALImproper Certificate ValidationEPSS 0.2%CVE-2026-82180CRITICALIn Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFiEPSS 0.2%CVE-2026-23776HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 0.2%CVE-2025-66491MEDIUMTraefik has Inverted TLS Verification Logic in its ingress-nginx ProviderEPSS 0.2%CVE-2026-59836MEDIUMA improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiCliEPSS 0.2%CVE-2025-69412LOWKDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which miEPSS 0.2%CVE-2025-64685HIGHIn JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosureEPSS 0.2%CVE-2026-56820HIGHNetty: Missing CertificateID Validation in OCSP Response Allows Replay AttacksEPSS 0.2%