Falhas do tipo CWE-295

856 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2024-28021HIGHA vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an aEPSS 0.3%CVE-2026-41016MEDIUMApache Airflow Providers SMTP: No certificate validation on SMTP STARTTLS connections in SMTP providerEPSS 0.3%CVE-2025-65830CRITICALDue to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstEPSS 0.3%CVE-2023-50315MEDIUMIBM WebSphere Application Server information disclosureEPSS 0.3%CVE-2026-76242CRITICALstigmem Federation Peer Registration Authentication BypassEPSS 0.3%CVE-2026-9258HIGHImproper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.3%CVE-2024-47119MEDIUMIBM Storage Defender - Resiliency Service improper certificate validationEPSS 0.3%CVE-2026-67294CRITICALFreeRDP before 3.29.0 TLS Certificate EKU BypassEPSS 0.3%CVE-2025-50944HIGHAn issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X5EPSS 0.3%CVE-2023-38686CRITICALSydent does not verify email server certificatesEPSS 0.3%CVE-2026-1530HIGHFog-kubevirt: fog-kubevirt: man-in-the-middle vulnerability due to disabled certificate validationEPSS 0.3%CVE-2026-90623MEDIUMandreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validationEPSS 0.3%CVE-2026-54919HIGHcpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backendsEPSS 0.3%CVE-2025-30279HIGHFile Station 5EPSS 0.3%CVE-2025-29884HIGHFile Station 5EPSS 0.3%CVE-2025-33031HIGHFile Station 5EPSS 0.3%CVE-2025-22486HIGHFile Station 5EPSS 0.3%CVE-2025-29885HIGHFile Station 5EPSS 0.3%CVE-2025-40801CRITICALA vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional TranslaEPSS 0.3%CVE-2025-29883HIGHFile Station 5EPSS 0.3%