Falhas do tipo CWE-295

856 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2026-20323HIGHCisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass VulnerabilityEPSS 0.1%CVE-2025-32745MEDIUMDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adEPSS 0.1%CVE-2026-8497HIGHImproper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on AndrEPSS 0.1%CVE-2023-21358HIGHIn UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypEPSS 0.1%CVE-2026-1068MEDIUMAn improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of interceptinEPSS 0.1%CVE-2024-42186LOWHCL BigFix Patch Download Plug-ins are affected by an insecure protocol supportEPSS 0.1%CVE-2024-14024LOWVideo StationEPSS 0.1%CVE-2026-40539HIGHAn improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 andEPSS 0.1%CVE-2026-16792HIGHGlobal TLS Certificate Validation Bypass in Lenovo XClarity OrchestratorEPSS 0.1%CVE-2026-12374MEDIUMImproper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperToolEPSS 0.1%CVE-2026-79975MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2026-0392HIGHeParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-updateEPSS 0.1%CVE-2026-24508LOWDell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerability. A low privilegeEPSS 0.1%CVE-2026-67231CRITICALRabbitMQ: Trust-store whitelist by Issuer+Serial onlyEPSS —CVE-2026-67404CRITICALRabbitMQ: OAuth2 silent verify_none fallback for JWKS fetchEPSS —CVE-2026-73587MEDIUMDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. AEPSS —