Falhas do tipo CWE-295

856 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2026-81034HIGHNetmaker through 1.6.0 Improper Certificate Validation in SMTP ClientEPSS 0.2%CVE-2026-40944MEDIUMOxia: TLS CA certificate chain validation fails with multi-certificate PEM bundlesEPSS 0.2%CVE-2026-22613MEDIUMThe server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacEPSS 0.2%CVE-2017-8445—An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manEPSS 0.2%CVE-2024-6156LOWMark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust storEPSS 0.2%CVE-2025-35983MEDIUMImproper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a liEPSS 0.2%CVE-2026-16107MEDIUMTS4500 CLI tool addresses security vulnerabilityEPSS 0.2%CVE-2026-81868MEDIUMSteeltoe: Header-forwarded client cert lacks proof of private-key possessionEPSS 0.2%CVE-2025-36290MEDIUMIBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certificate validation vulnerability in JWT service componentEPSS 0.2%CVE-2024-47241MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low priEPSS 0.2%CVE-2025-15323LOWTanium addressed an improper certificate validation vulnerability in Tanium Appliance.EPSS 0.2%CVE-2026-32884MEDIUMBotan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 Violation)EPSS 0.2%CVE-2024-6219LOWMark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restEPSS 0.2%CVE-2026-40971MEDIUMWhen configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to thEPSS 0.2%CVE-2026-57289MEDIUMJenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for coEPSS 0.2%CVE-2026-65325MEDIUMApache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verificationEPSS 0.2%CVE-2025-12943MEDIUMImproper certificate validation in firmware update logic in NETGEAR RAX30 and RAXE300EPSS 0.2%CVE-2026-22250LOWwlc can skip SSL verificationEPSS 0.2%CVE-2025-12047MEDIUMA vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances,EPSS 0.2%CVE-2024-48865HIGHQTS, QuTS heroEPSS 0.2%