Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2025-48393MEDIUMThe server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacEPSS 0.2%CVE-2021-20327MEDIUMMongoDB Node.js client side field level encryption library may not be validating KMS certificateEPSS 0.2%CVE-2025-35434LOWCISA Thorium does not validate TLS connections to ElasticsearchEPSS 0.2%CVE-2026-0277MEDIUMPrisma Access Agent: Improper Certificate Validation on iOSEPSS 0.2%CVE-2023-38009MEDIUMIBM Cognos Analytics Mobile information disclosureEPSS 0.2%CVE-2023-50178HIGHAn improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 aEPSS 0.2%CVE-2026-84081HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.2%CVE-2026-32144HIGHOCSP designated-responder authorization bypass via missing signature verificationEPSS 0.2%CVE-2025-23091MEDIUMAn Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-EPSS 0.2%CVE-2026-16822CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2026-10592MEDIUMWildcard DNS SAN bypasses CA name-constraint checksEPSS 0.2%CVE-2026-81871MEDIUMOpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinningEPSS 0.2%CVE-2026-73251CRITICALMongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verificationEPSS 0.2%CVE-2026-38974MEDIUMDulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.EPSS 0.2%CVE-2026-6091MEDIUMPartial-chain verification accepts untrusted intermediate as trust anchorEPSS 0.2%CVE-2025-62371HIGHOpenSearch Data Prepper plugins trusts all SSL certificates by defaultEPSS 0.2%CVE-2026-0228LOWPAN-OS: Improper Validation of Terminal Server Agent CertificateEPSS 0.2%CVE-2026-9259HIGHImproper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.2%CVE-2025-39205HIGHA vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-EPSS 0.2%CVE-2026-41132MEDIUMCKAN: No certificate validation on STMP connectionEPSS 0.2%