Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-81034HIGHNetmaker through 1.6.0 Improper Certificate Validation in SMTP ClientEPSS 0.2%CVE-2026-40944MEDIUMOxia: TLS CA certificate chain validation fails with multi-certificate PEM bundlesEPSS 0.2%CVE-2026-22613MEDIUMThe server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacEPSS 0.2%CVE-2017-8445An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manEPSS 0.2%CVE-2024-6156LOWMark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust storEPSS 0.2%CVE-2025-35983MEDIUMImproper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a liEPSS 0.2%CVE-2026-16107MEDIUMTS4500 CLI tool addresses security vulnerabilityEPSS 0.2%CVE-2026-81868MEDIUMSteeltoe: Header-forwarded client cert lacks proof of private-key possessionEPSS 0.2%CVE-2025-36290MEDIUMIBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certificate validation vulnerability in JWT service componentEPSS 0.2%CVE-2024-47241MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low priEPSS 0.2%CVE-2025-15323LOWTanium addressed an improper certificate validation vulnerability in Tanium Appliance.EPSS 0.2%CVE-2026-32884MEDIUMBotan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation)EPSS 0.2%CVE-2024-6219LOWMark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restEPSS 0.2%CVE-2026-40971MEDIUMWhen configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to thEPSS 0.2%CVE-2026-57289MEDIUMJenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for coEPSS 0.2%CVE-2026-65325MEDIUMApache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verificationEPSS 0.2%CVE-2025-12943MEDIUMImproper certificate validation in firmware update logic in NETGEAR RAX30 and RAXE300EPSS 0.2%CVE-2026-22250LOWwlc can skip SSL verificationEPSS 0.2%CVE-2025-12047MEDIUMA vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances,EPSS 0.2%CVE-2024-48865HIGHQTS, QuTS heroEPSS 0.2%