Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-24933HIGHAn improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.EPSS 0.2%CVE-2025-40744HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate cEPSS 0.2%CVE-2026-57826MEDIUMAn issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CEPSS 0.2%CVE-2025-10495HIGHA potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applicationEPSS 0.2%CVE-2024-41258MEDIUMAn issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing atEPSS 0.2%CVE-2025-71261HIGHHarvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOSEPSS 0.2%CVE-2026-22696CRITICALdcap-qvl has Missing Verification for QE IdentityEPSS 0.2%CVE-2025-40800CRITICALA vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < EPSS 0.2%CVE-2026-44213MEDIUMOpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configuredEPSS 0.2%CVE-2022-39334LOWnextcloudcmd incorrectly trusts bad TLS certificatesEPSS 0.2%CVE-2026-87608HIGHImproper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to EPSS 0.2%CVE-2024-41256MEDIUMDefault configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification EPSS 0.2%CVE-2026-48248HIGHOpen ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/login.inc.phpEPSS 0.2%CVE-2024-30134MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerabilityEPSS 0.2%CVE-2026-24122LOWCosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be OverlookedEPSS 0.2%CVE-2026-33308MEDIUMmod_gnutls missing key purpose check in client certificate verificationEPSS 0.2%CVE-2026-67598CRITICALEmlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.phpEPSS 0.2%CVE-2026-84197CRITICALIn Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and oEPSS 0.2%CVE-2026-6731MEDIUMX.509 name constraint bypass via Subject CN treated as a DNS nameEPSS 0.2%CVE-2025-62375MEDIUMgo-witness Improper Verification of AWS EC2 Identity DocumentsEPSS 0.2%