Falhas do tipo CWE-295

856 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2026-82955CRITICALIn the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API GaEPSS 0.1%CVE-2026-4396HIGHImproper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-EPSS 0.1%CVE-2026-4434HIGHImproper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack viEPSS 0.1%CVE-2026-87551MEDIUMImproper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bEPSS 0.1%CVE-2025-53869MEDIUMMultiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man-in-the-middle attacEPSS 0.1%CVE-2026-33248MEDIUMNATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingEPSS 0.1%CVE-2025-58781MEDIUMWTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.EPSS 0.1%CVE-2020-12614HIGHAn issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the nEPSS 0.1%CVE-2025-1001MEDIUMMedixant RadiAnt DICOM Viewer Improper Certificate ValidationEPSS 0.1%CVE-2022-32748HIGHA CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when usingEPSS 0.1%CVE-2026-13385CRITICALAn Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-theEPSS 0.1%CVE-2025-30000MEDIUMA vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restriEPSS 0.1%CVE-2026-15937MEDIUMAgent receiver certificate confusion allows authentication with a certificate issued for another endpointEPSS 0.1%CVE-2026-64993MEDIUMDell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated aEPSS 0.1%CVE-2024-47258HIGH2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates ofEPSS 0.1%CVE-2025-70044MEDIUMAn issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.EPSS 0.1%CVE-2026-0296MEDIUMGlobalProtect App: Improper Certificate Validation Bypass VulnerabilityEPSS 0.1%CVE-2025-64432MEDIUMKubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation LayerEPSS 0.1%CVE-2026-41119MEDIUMDell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated EPSS 0.1%CVE-2021-25635MEDIUMContent Manipulation with Certificate Validation AttackEPSS 0.1%