Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-52688HIGHRRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationEPSS 0.1%CVE-2026-44900HIGHepa4all-client: VAU Signature bypassEPSS 0.1%CVE-2025-8393HIGHDreame Technology iOS and Android Mobile Applications Improper Certificate ValidationEPSS 0.1%CVE-2026-2748HIGHS/MIME Certificate Subject WhitespaceEPSS 0.1%CVE-2026-29140HIGHS/MIME Signature Additional CertificateEPSS 0.1%CVE-2024-39771MEDIUMQBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacEPSS 0.1%CVE-2026-44309MEDIUMgitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commitsEPSS 0.1%CVE-2026-18679MEDIUMKong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configuredEPSS 0.1%CVE-2025-65083LOWGoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSigEPSS 0.1%CVE-2026-9758HIGHImproper Certificate Validation in S2OPCEPSS 0.1%CVE-2026-79691HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2025-2183MEDIUMGlobalProtect App: Improper Certificate Validation Leads to Privilege EscalationEPSS 0.1%CVE-2026-66760MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.1%CVE-2025-9785HIGHMisconfigured certificate validation with self-signed certificates for Print DeployEPSS 0.1%CVE-2026-78323MEDIUMJss: jss: jsstrustmanager does not verify nss trust flags on ca certificatesEPSS 0.1%CVE-2026-79642MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2026-79732LOWDell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validation vulnerability. AnEPSS 0.1%CVE-2026-0249MEDIUMGlobalProtect App: Certificate Validation Bypass VulnerabilitiesEPSS 0.1%CVE-2019-25652HIGHUniFi Network Controller Improper Certificate Validation Leading to Credential Theft via MITMEPSS 0.1%CVE-2026-87571MEDIUMImproper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering toEPSS 0.1%