CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,455 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 25 of 30
- CVE-2025-40800HIGHCVSS 7.4EG 7.42025-12-09
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcen…
- CVE-2025-40801HIGHCVSS 8.1EG 8.12025-12-09
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as…
- CVE-2025-40896MEDIUMCVSS 4.8EG 6.52026-03-04
The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This cou…
- CVE-2025-42611MEDIUMCVSS 6.5EG 6.52026-05-05
RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerab…
- CVE-2025-44018HIGHCVSS 8.3EG 8.32025-11-24
A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulne…
- CVE-2025-44964LOWCVSS 3.9EG 3.92025-08-05
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information.
- CVE-2025-4575MEDIUMCVSS 6.5EG 6.52025-05-22
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it wil…
- CVE-2025-46070CRITICALCVSS 9.8EG 9.82026-01-12
An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component
- CVE-2025-46551LOWCVSS 3.7EG 3.72025-05-07
JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.…
- CVE-2025-46788HIGHCVSS 7.4EG 7.42025-07-10
Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.
- CVE-2025-48393MEDIUMCVSS 5.7EG 5.72025-08-06
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmwar…
- CVE-2025-48802MEDIUMCVSS 6.5EG 6.52025-07-08
Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.
- CVE-2025-4947MEDIUMCVSS 6.5EG 6.52025-05-28
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.
- CVE-2025-5025MEDIUMCVSS 4.8EG 4.82025-05-28
libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works…
- CVE-2025-50944HIGHCVSS 8.8EG 8.82025-09-15
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping p…
- CVE-2025-52598LOWCVSS 3.7EG 3.72025-12-26
Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has found a flaw that camera's client service does not perform certificate validation. The manufacturer has…
- CVE-2025-5279HIGHCVSS 7.0EG 7.02025-05-27
When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. An insecure connection could allow an actor to i…
- CVE-2025-52919MEDIUMCVSS 4.3EG 4.32025-06-21
In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.
- CVE-2025-53869LOWCVSS 3.7EG 3.72026-01-29
Multiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man-in-the-middle attacker to replace the set of root certificates used by the product with a set of arbitrary certificate…
- CVE-2025-54470HIGHCVSS 8.6EG 8.62025-10-30
This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server. In affected versions, NeuVecto…
- CVE-2025-54607HIGHCVSS 7.7EG 7.72025-08-06
Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-54809HIGHCVSS 7.4EG 7.42025-08-13
F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2025-55109CRITICALCVSS 9.0EG 9.02025-09-16
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote …
- CVE-2025-56231CRITICALCVSS 9.1EG 9.12025-11-05
Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.
- CVE-2025-58123MEDIUMCVSS 4.8EG 4.82025-08-28
Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.
- CVE-2025-58124MEDIUMCVSS 4.8EG 4.82025-08-28
Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.
- CVE-2025-58125MEDIUMCVSS 4.8EG 4.82025-08-28
Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to intercept traffic.
- CVE-2025-58126MEDIUMCVSS 4.8EG 4.82025-08-28
Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic.
- CVE-2025-58127MEDIUMCVSS 4.8EG 4.82025-08-28
Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic.
- CVE-2025-58188HIGHCVSS 7.5EG 7.52025-10-29
Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.
- CVE-2025-58781MEDIUMCVSS 4.8EG 4.82025-09-12
WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.
- CVE-2025-59347MEDIUMCVSS 6.5EG 6.52025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clients are not configurable, so users have no way to re-enable t…
- CVE-2025-59353HIGHCVSS 7.5EG 7.52025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue i…
- CVE-2025-60022MEDIUMCVSS 4.8EG 4.82025-11-17
Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man-in-the-middle attack may allow an attacker to eavesdrop on and/or tamper with an encr…
- CVE-2025-6026LOWCVSS 3.1EG 3.12025-10-15
An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geoloca…
- CVE-2025-6032HIGHCVSS 8.3EG 8.32025-06-24
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
- CVE-2025-6037MEDIUMCVSS 6.8EG 6.82025-08-01
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cer…
- CVE-2025-61727MEDIUMCVSS 6.5EG 6.52025-12-03
An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from cl…
- CVE-2025-61729HIGHCVSS 7.5EG 7.52025-12-02
Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime…
- CVE-2025-61778CRITICALCVSS 9.3EG 9.32025-10-06
Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private…
- CVE-2025-62371HIGHCVSS 7.4EG 7.42025-10-15
OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided…
- CVE-2025-62375MEDIUMCVSS 6.9EG 6.92025-10-15
go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness versions 0.9.2 and earlier the AWS attestor improperly verifies AWS EC2 instance identity documents. Verification can i…
- CVE-2025-6433CRITICALCVSS 9.8EG 9.82025-06-24
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requi…
- CVE-2025-64432MEDIUMCVSS 4.7EG 4.72025-11-07
KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. It …
- CVE-2025-64685HIGHCVSS 7.5EG 8.12025-11-10
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
- CVE-2025-65083LOWCVSS 3.2EG 3.22025-11-17
GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSign Desktop user selects an arbitrary proxy server without consideration of whether outbound HTTPS co…
- CVE-2025-65290HIGHCVSS 7.4EG 7.42025-12-10
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic …
- CVE-2025-65291HIGHCVSS 7.4EG 7.42025-12-10
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks o…
- CVE-2025-65753CRITICALCVSS 7.5EG 9.02026-02-17
An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.
- CVE-2025-65830CRITICALCVSS 9.1EG 9.12025-12-10
Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstream" can decrypt the TLS traffic, inspect its contents, and modify the requests in transit. This m…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →