Falhas do tipo CWE-295

853 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2026-4370CRITICALImproper TLS Client/Server authentication and certificate verification on Database ClusterEPSS 0.4%CVE-2022-1834MEDIUMWhen displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird EPSS 0.4%CVE-2023-6680HIGHImproper Certificate Validation in GitLabEPSS 0.4%CVE-2024-52329CRITICALECOVACS HOME mobile app plugins do not properly validate TLS certificatesEPSS 0.4%CVE-2024-41334HIGHDraytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior EPSS 0.4%CVE-2022-31733CRITICALStarting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another EPSS 0.4%CVE-2025-10548MEDIUMMissing Certificate Validation in CleverControl Installer Allows Remote Code ExecutionEPSS 0.4%CVE-2023-5594HIGHImproper following of a certificate's chain of trust in ESET security productsEPSS 0.4%CVE-2022-1197MEDIUMWhen importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the keyEPSS 0.4%CVE-2022-40147A vulnerability has been identified in Industrial Edge Management (All versions < V1.5.1). The affected software does not properly validate EPSS 0.4%CVE-2025-24471MEDIUMAn Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP veriEPSS 0.4%CVE-2026-27134HIGHStrimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autenticationEPSS 0.4%CVE-2023-0430MEDIUMCertificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayEPSS 0.4%CVE-2023-0547MEDIUMOCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be acceEPSS 0.4%CVE-2024-54849MEDIUMAn issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a EPSS 0.4%CVE-2024-10445MEDIUMImproper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskEPSS 0.4%CVE-2022-45419MEDIUMIf the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certifiEPSS 0.4%CVE-2024-48915HIGHAgent Dart missing certificate verification checksEPSS 0.4%CVE-2026-65084HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation.EPSS 0.4%CVE-2025-66001HIGHNeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)EPSS 0.4%