CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,455 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 16 of 30
- CVE-2021-43114HIGHCVSS 7.5EG 7.52021-11-09
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
- CVE-2021-43766HIGHCVSS 8.1EG 8.12022-08-25
Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first…
- CVE-2021-43767MEDIUMCVSS 5.9EG 5.92022-08-25
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-mi…
- CVE-2021-43882CRITICALCVSS 9.0EG 9.82021-12-15
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2021-44273HIGHCVSS 7.4EG 7.42021-12-23
e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, di…
- CVE-2021-44531HIGHCVSS 7.4EG 7.42022-02-24
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was …
- CVE-2021-44532MEDIUMCVSS 5.3EG 5.32022-02-24
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject…
- CVE-2021-44533MEDIUMCVSS 5.3EG 5.32022-02-24
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpr…
- CVE-2021-44549HIGHCVSS 7.4EG 7.42021-12-14
Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "man in the middle" attacks additional server identity checks must be performed when access…
- CVE-2021-45035MEDIUMCVSS 6.3EG 6.32022-09-23
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.
- CVE-2021-45490CRITICALCVSS 9.1EG 9.12022-03-28
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.
- CVE-2021-46880CRITICALCVSS 9.8EG 9.82023-04-15
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
- CVE-2022-0123MEDIUMCVSS 5.9EG 6.82022-03-28
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform…
- CVE-2022-0759HIGHCVSS 8.1EG 8.12022-03-25
A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubecli…
- CVE-2022-1197MEDIUMCVSS 5.4EG 5.42022-12-22
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that…
- CVE-2022-1343MEDIUMCVSS 5.3EG 5.32022-05-03
The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case wh…
- CVE-2022-1632MEDIUMCVSS 6.5EG 6.52022-09-01
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to e…
- CVE-2022-1805HIGHCVSS 8.1EG 8.12022-07-28
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and A…
- CVE-2022-1834MEDIUMCVSS 6.5EG 6.52022-12-22
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. This could have been used by an attacker to send an email mess…
- CVE-2022-20034MEDIUMCVSS 6.8EG 6.82022-02-09
In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution…
- CVE-2022-20071MEDIUMCVSS 6.7EG 6.72022-04-11
In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID…
- CVE-2022-20081MEDIUMCVSS 5.9EG 5.92022-04-11
In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation…
- CVE-2022-20703CRITICALCVSS 10.0EG 10.0⚠ KEV2022-02-10
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication a…
- CVE-2022-20813CRITICALCVSS 9.0EG 9.02022-07-06
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byt…
- CVE-2022-20814HIGHCVSS 7.4EG 7.42024-11-15
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to …
- CVE-2022-20860HIGHCVSS 7.4EG 7.42022-07-21
A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL…
- CVE-2022-20960HIGHCVSS 7.5EG 7.52022-11-04
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper …
- CVE-2022-21170LOWCVSS 3.7EG 3.72022-03-10
Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILTER Browser & Cloud MultiAgent for Windows Ver.4.93R04 and earlier, and D-SPA (Ver.3 / Ver.4) using i-FILTER allows a re…
- CVE-2022-21654HIGHCVSS 7.4EG 7.42022-02-22
Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to en…
- CVE-2022-21656HIGHCVSS 7.4EG 7.42022-02-22
Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the default certificate validation routines has a "type confusion" bug when processing subjec…
- CVE-2022-21657MEDIUMCVSS 6.8EG 6.82022-02-22
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certificates it accepts from the peer, either as a TLS client or a TLS server, to only those ce…
- CVE-2022-21836HIGHCVSS 7.8EG 7.82022-01-11
Windows Certificate Spoofing Vulnerability
- CVE-2022-22156MEDIUMCVSS 6.5EG 6.52022-01-19
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may comprom…
- CVE-2022-22305MEDIUMCVSS 5.4EG 5.42023-09-01
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network …
- CVE-2022-22306MEDIUMCVSS 5.4EG 5.42022-05-24
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication b…
- CVE-2022-22380MEDIUMCVSS 5.0EG 5.02023-10-17
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957.
- CVE-2022-22549HIGHCVSS 7.5EG 8.12022-04-12
Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vulnerability, leading to a man-in-the-middle capture of administrative credentials.
- CVE-2022-22747MEDIUMCVSS 6.5EG 6.52022-12-22
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96,…
- CVE-2022-22787HIGHCVSS 5.9EG 7.52022-05-18
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an un…
- CVE-2022-22885CRITICALCVSS 9.8EG 9.82022-02-16
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
- CVE-2022-22946MEDIUMCVSS 5.5EG 5.52022-03-04
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect…
- CVE-2022-23632HIGHCVSS 7.4EG 7.42022-02-17
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configur…
- CVE-2022-23649LOWCVSS 3.3EG 3.32022-02-18
Cosign provides container signing, verification, and storage in an OCI registry for the sigstore project. Prior to version 1.5.2, Cosign can be manipulated to claim that an entry for a signature exists in the Rekor transparency log even if…
- CVE-2022-24319MEDIUMCVSS 5.9EG 5.92022-02-09
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStr…
- CVE-2022-24320MEDIUMCVSS 5.9EG 5.92022-02-09
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affected Product: ClearSCADA (All Versions), E…
- CVE-2022-24901HIGHCVSS 7.5EG 7.52022-05-04
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL …
- CVE-2022-24968MEDIUMCVSS 5.9EG 5.92022-02-11
In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs becaus…
- CVE-2022-25243MEDIUMCVSS 6.5EG 6.52022-03-10
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_s…
- CVE-2022-25638MEDIUMCVSS 6.5EG 6.52022-02-24
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate…
- CVE-2022-25640HIGHCVSS 7.5EG 7.52022-02-24
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →