Falhas do tipo CWE-295

854 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2026-50302MEDIUMWindows Cryptographic Services Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2024-29171MEDIUMDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote EPSS 0.3%CVE-2024-27323HIGHPDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-32293MEDIUMGL-iNet Comet (GL-RM1) KVM insufficient certificate validationEPSS 0.3%CVE-2026-42789HIGHNon-CA certificate accepted as intermediate issuer in public_key path validationEPSS 0.3%CVE-2026-6450LOWCRL critical extension bypass in ParseCRL_ExtensionsEPSS 0.3%CVE-2026-85102CRITICALImproper Certificate Validation in Quantum Security GatewayEPSS 0.3%KEVCVE-2020-25680A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknowEPSS 0.3%CVE-2025-44018HIGHA firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can leaEPSS 0.3%CVE-2023-31421MEDIUMBeats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issueEPSS 0.3%CVE-2023-30517MEDIUMJenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when coEPSS 0.3%CVE-2024-43177MEDIUMIBM Concert improper certificate validationEPSS 0.3%CVE-2026-46428CRITICALlettre has TLS hostname verification disabled when using Boring TLS backendEPSS 0.3%CVE-2026-66795CRITICALManagedcluster-import-controller: csr auto-approver does not validate certificate subject or signername (spoke→hub cluster-admin)EPSS 0.3%CVE-2025-20670MEDIUMIn Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, ifEPSS 0.3%CVE-2023-1514HIGHA vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certEPSS 0.3%CVE-2026-25644HIGHDataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgradeEPSS 0.3%CVE-2026-42791MEDIUMOCSP responder certificate validity period not checked in public_keyEPSS 0.3%CVE-2018-19946MEDIUMThe vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerabilitEPSS 0.3%CVE-2021-32755MEDIUMCertificate pinning is not enforced on the web socket connectionEPSS 0.3%