CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,455 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 19 of 30
- CVE-2023-23901MEDIUMCVSS 6.5EG 6.52023-05-10
Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, which may allow a remote unauthenticated attacker to eavesdro…
- CVE-2023-2422MEDIUMCVSS 5.5EG 5.52023-10-04
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as …
- CVE-2023-24461HIGHCVSS 7.4EG 7.42023-05-03
An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system. Note: Software versions which have reached End of Technical Support (…
- CVE-2023-24568HIGHCVSS 5.0EG 7.42023-05-30
Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replacing CA signed certificates.
- CVE-2023-25392MEDIUMCVSS 5.9EG 5.92023-04-10
Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.
- CVE-2023-26463CRITICALCVSS 9.8EG 9.82023-04-15
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired po…
- CVE-2023-27823CRITICALCVSS 9.8EG 9.82023-05-12
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
- CVE-2023-28093MEDIUMCVSS 6.5EG 6.52023-04-10
A user with a compromised configuration can start an unsigned binary as a service.
- CVE-2023-28321MEDIUMCVSS 5.9EG 5.92023-05-26
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matchi…
- CVE-2023-28807MEDIUMCVSS 5.1EG 5.12024-01-31
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
- CVE-2023-29000MEDIUMCVSS 5.4EG 5.42023-04-04
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a mal…
- CVE-2023-29175MEDIUMCVSS 4.8EG 4.82023-06-13
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a r…
- CVE-2023-29501MEDIUMCVSS 4.8EG 4.82023-06-13
Jiyu Kukan Toku-Toku coupon App for iOS versions 3.5.0 and earlier, and Jiyu Kukan Toku-Toku coupon App for Android versions 3.5.0 and earlier are vulnerable to improper server certificate verification. If this vulnerability is exploited, …
- CVE-2023-30222HIGHCVSS 7.5EG 7.52023-06-16
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
- CVE-2023-30516MEDIUMCVSS 6.5EG 6.52023-04-12
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2…
- CVE-2023-30517MEDIUMCVSS 5.3EG 5.92023-04-12
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.
- CVE-2023-30729HIGHCVSS 8.1EG 8.12023-09-06
Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.
- CVE-2023-31151MEDIUMCVSS 4.7EG 4.72023-05-10
An Improper Certificate Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote unauthenticated attacker to conduct a man-in-the-middle (MitM) att…
- CVE-2023-31190HIGHCVSS 8.1EG 8.12023-07-11
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure. Specifically, the firmware update procedure ignores and does not check the validi…
- CVE-2023-31421MEDIUMCVSS 5.9EG 5.92023-10-26
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still perf…
- CVE-2023-31484HIGHCVSS 8.1EG 8.12023-04-29
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
- CVE-2023-31485MEDIUMCVSS 5.9EG 5.92023-04-29
GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.
- CVE-2023-31486HIGHCVSS 8.1EG 8.12023-04-29
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
- CVE-2023-31580MEDIUMCVSS 5.9EG 5.92023-10-25
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.
- CVE-2023-32330HIGHCVSS 7.5EG 7.52024-02-07
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.
- CVE-2023-32464LOWCVSS 2.7EG 2.72023-06-23
Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted …
- CVE-2023-32994LOWCVSS 3.7EG 3.72023-05-16
Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middl…
- CVE-2023-33201MEDIUMCVSS 5.3EG 5.32023-07-05
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation …
- CVE-2023-33295MEDIUMCVSS 6.5EG 6.52024-01-19
Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.
- CVE-2023-33757MEDIUMCVSS 5.9EG 5.92024-01-25
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.
- CVE-2023-33760MEDIUMCVSS 5.3EG 5.32024-01-25
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.
- CVE-2023-33861MEDIUMCVSS 6.5EG 6.52025-05-20
IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.
- CVE-2023-34143MEDIUMCVSS 5.6EG 5.62023-07-18
Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Man in the Middle Attack.This issue affect…
- CVE-2023-34410MEDIUMCVSS 5.3EG 5.32023-06-05
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
- CVE-2023-34414LOWCVSS 3.1EG 3.12023-06-19
The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If a malicious page elicited user clicks i…
- CVE-2023-35142HIGHCVSS 8.1EG 8.12023-06-14
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
- CVE-2023-35721HIGHCVSS 8.8EG 8.82024-05-03
NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of…
- CVE-2023-35845MEDIUMCVSS 4.7EG 4.72023-09-11
Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask…
- CVE-2023-3615HIGHCVSS 8.1EG 8.12023-07-17
Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.
- CVE-2023-3724CRITICALCVSS 9.1EG 9.12023-07-17
If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the s…
- CVE-2023-37397LOWCVSS 3.6EG 3.62024-04-19
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672.
- CVE-2023-38009MEDIUMCVSS 4.2EG 4.22025-01-26
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
- CVE-2023-38325HIGHCVSS 7.5EG 7.52023-07-14
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
- CVE-2023-38351HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38352HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38353MEDIUMCVSS 5.9EG 5.92023-09-19
MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.
- CVE-2023-38354HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38355HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38356HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38686CRITICALCVSS 9.3EG 9.32023-08-04
Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception …
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →