Falhas do tipo CWE-295

856 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2026-41119MEDIUMDell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated EPSS 0.1%CVE-2025-40745MEDIUMA vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), SimcenteEPSS 0.1%CVE-2026-90647CRITICALASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in thEPSS 0.1%CVE-2026-40970MEDIUMWhen configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting EPSS 0.1%CVE-2026-80122HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2024-4786LOWAn improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device EPSS 0.1%CVE-2026-25834MEDIUMMbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.EPSS 0.1%CVE-2026-74774MEDIUMDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker wiEPSS 0.1%CVE-2025-8476HIGHAlpine iLX-507 TIDAL Improper Certificate Validation VulnerabilityEPSS 0.1%CVE-2026-65129MEDIUMNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successEPSS 0.1%CVE-2025-60022LOWImproper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a maEPSS 0.1%CVE-2026-65118HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successEPSS 0.1%CVE-2026-78483MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2026-41714MEDIUMIn Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManagerEPSS 0.1%CVE-2026-78489MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2024-32865MEDIUMexacqVison - TLS certificate validationEPSS 0.1%CVE-2025-9291HIGHImproper Certificate Validation in TP-Link Omada Cloud CommunicationsEPSS 0.1%CVE-2025-26478LOWDell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent netwoEPSS 0.1%CVE-2026-66154HIGHAn insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) aEPSS 0.1%CVE-2026-79734MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%