Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2025-70045HIGHAn issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certifEPSS 0.2%CVE-2026-79785HIGHX-AnyLabeling before 4.0.0-beta.9 Improper Certificate Validation in Model DownloadsEPSS 0.2%CVE-2025-11695HIGHConfiguration may unexpectedly disable certificate validationEPSS 0.2%CVE-2024-8287HIGHAnbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent.EPSS 0.2%CVE-2025-0309MEDIUMNetskope Client Local Elevation of PrivilegesEPSS 0.2%CVE-2025-65290HIGHAqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HEPSS 0.2%CVE-2026-0233LOWAutonomous Digital Experience Manager: Improper validation of ADEM certificateEPSS 0.2%CVE-2025-65291HIGHAqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS conneEPSS 0.2%CVE-2026-18089HIGHNet::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configuredEPSS 0.2%CVE-2026-42312MEDIUMpyload-ng: non-admin SETTINGS users can disable outbound TLS peer verificationEPSS 0.2%CVE-2026-48247HIGHOpen ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/functions.inc.phpEPSS 0.2%CVE-2024-31854HIGHA vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS serveEPSS 0.2%CVE-2026-40243LOWIncus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonationEPSS 0.2%CVE-2024-31853HIGHA vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS serveEPSS 0.2%CVE-2026-48249HIGHOpen ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in rm/incs/mobile_login.inc.phpEPSS 0.2%CVE-2025-36005MEDIUMIBM MQ Operator information disclosureEPSS 0.2%CVE-2026-44393HIGHAn issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname vEPSS 0.2%CVE-2026-5263HIGHURI nameConstraints not enforced in ConfirmNameConstraints()EPSS 0.2%CVE-2023-6043HIGHA privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and executeEPSS 0.2%CVE-2025-20126MEDIUMCisco ThousandEyes Endpoint Agent Certificate Validation VulnerabilityEPSS 0.2%