Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-82955CRITICALIn the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API GaEPSS 0.1%CVE-2026-4396HIGHImproper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-EPSS 0.1%CVE-2026-4434HIGHImproper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack viEPSS 0.1%CVE-2026-87551MEDIUMImproper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bEPSS 0.1%CVE-2025-53869MEDIUMMultiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man-in-the-middle attacEPSS 0.1%CVE-2026-33248MEDIUMNATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingEPSS 0.1%CVE-2025-58781MEDIUMWTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.EPSS 0.1%CVE-2020-12614HIGHAn issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the nEPSS 0.1%CVE-2025-1001MEDIUMMedixant RadiAnt DICOM Viewer Improper Certificate ValidationEPSS 0.1%CVE-2022-32748HIGHA CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when usingEPSS 0.1%CVE-2026-13385CRITICALAn Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-theEPSS 0.1%CVE-2025-30000MEDIUMA vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restriEPSS 0.1%CVE-2026-15937MEDIUMAgent receiver certificate confusion allows authentication with a certificate issued for another endpointEPSS 0.1%CVE-2026-64993MEDIUMDell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated aEPSS 0.1%CVE-2024-47258HIGH2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates ofEPSS 0.1%CVE-2025-70044MEDIUMAn issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.EPSS 0.1%CVE-2026-0296MEDIUMGlobalProtect App: Improper Certificate Validation Bypass VulnerabilityEPSS 0.1%CVE-2025-64432MEDIUMKubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation LayerEPSS 0.1%CVE-2026-41119MEDIUMDell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated EPSS 0.1%CVE-2021-25635MEDIUMContent Manipulation with Certificate Validation AttackEPSS 0.1%