Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-56820HIGHNetty: Missing CertificateID Validation in OCSP Response Allows Replay AttacksEPSS 0.2%CVE-2025-64685HIGHIn JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosureEPSS 0.2%CVE-2024-31340MEDIUMTP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, which may allow a reEPSS 0.2%CVE-2025-64649MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2026-0244MEDIUMPrisma SD-WAN: Improper Certificate Validation VulnerabilityEPSS 0.2%CVE-2026-16835CRITICALPower System Improper Certificate ValidationEPSS 0.2%CVE-2025-15612MEDIUMWazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCEEPSS 0.2%CVE-2026-18717CRITICALImproper Certificate Validation in ASE 2000EPSS 0.2%CVE-2025-12765HIGHpgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass.EPSS 0.2%CVE-2026-23998HIGHFleet has a Windows MDM management endpoint authentication bypassEPSS 0.2%CVE-2026-24932HIGHAn improper certificate validation vulnerability was found in ADM while updating the DDNS settings.EPSS 0.2%CVE-2023-47537MEDIUMAn improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, FortiOS 7.0.0 throughEPSS 0.2%CVE-2023-6056HIGHInsecure Trust of Self-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11164)EPSS 0.2%CVE-2025-2028MEDIUMLack of TLS validationEPSS 0.2%CVE-2023-49570HIGHInsecure Trust of Basic Constraints certificate in Bitdefender Total Security HTTPS Scanning (VA-11210)EPSS 0.2%CVE-2026-57826MEDIUMAn issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CEPSS 0.2%CVE-2023-6057HIGHInsecure Trust of DSA-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11166)EPSS 0.2%CVE-2025-40744HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate cEPSS 0.2%CVE-2026-73253CRITICALMongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard MatchingEPSS 0.2%CVE-2026-78234CRITICALHawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit usersEPSS 0.2%