Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-9036MEDIUMVulnerabilities exists in IBM Netezza SoftwareEPSS 0.1%CVE-2026-2368HIGHAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2026-45175HIGHIdira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation ProcessesEPSS 0.1%CVE-2021-22278MEDIUMCertificate verification vulnerability in Update Manager of PCM600 Engineering ToolEPSS 0.1%CVE-2026-13327HIGHImproper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positiEPSS 0.1%CVE-2026-8367MEDIUMaria2c Improper Certificate ValidationEPSS 0.1%CVE-2026-91812HIGHFoxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation VulnerabilityEPSS 0.1%CVE-2024-35140HIGHIBM Security Verify Access privilege escalationEPSS 0.1%CVE-2026-8480MEDIUMConnection possible to the Administration portal with a revoked certificateEPSS 0.1%CVE-2024-45205HIGHAn Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) couldEPSS 0.1%CVE-2026-81447MEDIUMDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticaEPSS 0.1%CVE-2026-66404MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on thEPSS 0.1%CVE-2026-54342HIGHTLS Certificate Verification Disabled on CXF Transport Clients in epa4allEPSS 0.1%CVE-2026-82662HIGHNodemailer before 8.0.8 TLS Certificate Validation BypassEPSS 0.1%CVE-2026-48021CRITICALepa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vauEPSS 0.1%CVE-2024-47477MEDIUMDell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attackEPSS 0.1%CVE-2026-40992MEDIUMMail Auto-Configuration Does Not Enable SSL Hostname VerificationEPSS 0.1%CVE-2026-79736LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2026-79729LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2026-79690LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%