Falhas do tipo CWE-295

856 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2025-11043CRITICALImproper Server Certificate Validation in Automation StudioEPSS 0.2%CVE-2025-56231CRITICALTonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass updaEPSS 0.2%CVE-2022-45856MEDIUMAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 aEPSS 0.2%CVE-2024-37311HIGHCollabora Online's remote host TLS certificates are not fully verifiedEPSS 0.2%CVE-2026-63650LOWOpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 usernaEPSS 0.2%CVE-2024-50691HIGHSunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certifEPSS 0.2%CVE-2026-47074HIGHex_aws_sns SigningCertURL not validated in verify_message/1EPSS 0.2%CVE-2025-0239MEDIUMAlt-Svc ALPN validation failure when redirectedEPSS 0.2%CVE-2024-23970MEDIUMChargePoint Home Flex Improper Certificate ValidationEPSS 0.2%CVE-2026-58162HIGHApache Traffic Server: Certifier plugin trusts client SNI when generating certificatesEPSS 0.2%CVE-2026-45388CRITICALIn OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersEPSS 0.2%CVE-2024-27440MEDIUMThe Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly veEPSS 0.2%CVE-2026-6900CRITICALImproper Certificate ValidationEPSS 0.2%CVE-2026-82180CRITICALIn Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFiEPSS 0.2%CVE-2026-23776HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 0.2%CVE-2025-66491MEDIUMTraefik has Inverted TLS Verification Logic in its ingress-nginx ProviderEPSS 0.2%CVE-2026-59836MEDIUMA improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiCliEPSS 0.2%CVE-2025-69412LOWKDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which miEPSS 0.2%CVE-2025-64685HIGHIn JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosureEPSS 0.2%CVE-2026-56820HIGHNetty: Missing CertificateID Validation in OCSP Response Allows Replay AttacksEPSS 0.2%