Fallos del tipo CWE-295

856 resultados

Validação inadequada de certificados SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de domínios diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação mesmo com criptografia, comprometendo a confidencialidade e integridade dos dados.

Ejemplo

Uma API cliente ignora erros de validação de certificado (ex: desabilita verificação de hostname ou ignora exceções de certificado inválido) e faz requisições HTTPS para servidores externos. Um atacante na rede intercepta o tráfego, apresenta seu próprio certificado, e consegue ler dados sensíveis como tokens de autenticação ou credenciais.

Cómo mitigar

Sempre validar certificados: verificar hostname, data de validade e cadeia de confiança. Usar bibliotecas padrão do seu runtime (HttpClient do .NET, requests do Python, etc.) com validação ativada por padrão. Nunca desabilitar validação SSL/TLS em produção; se precisar em desenvolvimento, use variáveis de ambiente e revise criticamente o código antes de deploy.

CVE-2026-20323HIGHCisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass VulnerabilityEPSS 0.1%CVE-2025-32745MEDIUMDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adEPSS 0.1%CVE-2026-8497HIGHImproper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on AndrEPSS 0.1%CVE-2023-21358HIGHIn UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypEPSS 0.1%CVE-2026-1068MEDIUMAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2024-42186LOWHCL BigFix Patch Download Plug-ins are affected by an insecure protocol supportEPSS 0.1%CVE-2024-14024LOWVideo StationEPSS 0.1%CVE-2026-40539HIGHAn improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 andEPSS 0.1%CVE-2026-16792HIGHGlobal TLS Certificate Validation Bypass in Lenovo XClarity OrchestratorEPSS 0.1%CVE-2026-12374MEDIUMImproper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperToolEPSS 0.1%CVE-2026-79975MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2026-0392HIGHeParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-updateEPSS 0.1%CVE-2026-24508LOWDell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerability. A low privilegeEPSS 0.1%CVE-2026-67231CRITICALRabbitMQ: Trust-store whitelist by Issuer+Serial onlyEPSS CVE-2026-67404CRITICALRabbitMQ: OAuth2 silent verify_none fallback for JWKS fetchEPSS CVE-2026-73587MEDIUMDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. AEPSS