CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,582 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 3 of 32
- CVE-2016-10931HIGHCVSS 8.1EG 8.12019-08-26
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.
- CVE-2016-10937HIGHCVSS 7.5EG 7.52019-09-08
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
- CVE-2016-11076MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
- CVE-2016-11086HIGHCVSS 7.4EG 7.42020-09-24
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informatio…
- CVE-2016-1132HIGHCVSS 7.5EG 7.52017-04-13
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.
- CVE-2016-1148HIGHCVSS 8.1EG 8.12017-04-21
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.
- CVE-2016-1184MEDIUMCVSS 5.9EG 5.92017-04-21
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.
- CVE-2016-1186MEDIUMCVSS 5.9EG 5.92017-04-21
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
- CVE-2016-1198MEDIUMCVSS 5.9EG 5.92017-04-21
Photopt for Android before 2.0.1 does not verify SSL certificates.
- CVE-2016-1210MEDIUMCVSS 5.9EG 5.92017-04-21
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2016-1221MEDIUMCVSS 5.9EG 5.92017-04-21
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2016-1252MEDIUMCVSS 5.9EG 5.92017-12-05
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-mid…
- CVE-2016-1519MEDIUMCVSS 5.9EG 5.92017-04-21
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted …
- CVE-2016-20011HIGHCVSS 7.5EG 7.52021-05-25
libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.
- CVE-2016-2402MEDIUMCVSS 5.9EG 5.92017-01-30
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
- CVE-2016-2922MEDIUMCVSS 3.7EG 5.92018-08-13
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server …
- CVE-2016-3083HIGHCVSS 7.5EG 7.52017-05-30
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the client in Apache Hive before 1.2.2 and 2.0.x …
- CVE-2016-4467MEDIUMCVSS 5.9EG 5.92017-05-02
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50…
- CVE-2016-4818MEDIUMCVSS 5.9EG 5.92017-04-20
DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.
- CVE-2016-4829MEDIUMCVSS 5.9EG 5.92017-04-21
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.
- CVE-2016-4830MEDIUMCVSS 5.9EG 5.92017-04-21
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.
- CVE-2016-4832MEDIUMCVSS 5.9EG 5.92017-04-21
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.
- CVE-2016-4840MEDIUMCVSS 5.9EG 5.92017-04-21
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
- CVE-2016-5016MEDIUMCVSS 5.9EG 5.92017-04-24
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x bef…
- CVE-2016-5648MEDIUMCVSS 5.3EG 5.32017-06-08
Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.
- CVE-2016-6562HIGHCVSS 7.5EG 7.52018-07-13
On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position to perform MITM attacks may be able to o…
- CVE-2016-7075HIGHCVSS 7.5EG 8.12018-09-10
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially cr…
- CVE-2016-7171MEDIUMCVSS 5.6EG 5.62016-12-05
NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation.
- CVE-2016-7662HIGHCVSS 7.5EG 7.52017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which allows remote attackers to spoof certifi…
- CVE-2016-7805MEDIUMCVSS 5.9EG 5.92017-06-09
The mobiGate App for Android version 2.2.1.2 and earlier and mobiGate App for iOS version 2.2.4.1 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive…
- CVE-2016-7815MEDIUMCVSS 4.2EG 4.22017-04-28
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.
- CVE-2016-7816MEDIUMCVSS 5.9EG 5.92017-06-09
The Cybozu kintone mobile for Android 1.0.6 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVE-2016-8231HIGHCVSS 7.5EG 7.52017-06-04
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.
- CVE-2016-9015LOWCVSS 3.7EG 3.72017-01-11
Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk…
- CVE-2016-9064MEDIUMCVSS 5.9EG 5.92018-06-11
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the …
- CVE-2016-9319MEDIUMCVSS 5.9EG 5.92017-03-31
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
- CVE-2016-9892MEDIUMCVSS 5.9EG 5.92017-03-02
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle at…
- CVE-2016-9952HIGHCVSS 8.1EG 8.12018-03-12
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted wild…
- CVE-2017-0129HIGHCVSS 7.5EG 7.52017-03-17
Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft Lync for Mac Certificate Validation Vulnerability."
- CVE-2017-0248HIGHCVSS 7.5EG 7.52017-05-12
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass V…
- CVE-2017-1000007MEDIUMCVSS 5.9EG 5.92017-07-17
txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.
- CVE-2017-1000097HIGHCVSS 7.5EG 7.52017-10-05
On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certifica…
- CVE-2017-1000209MEDIUMCVSS 5.9EG 5.92017-11-17
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to sp…
- CVE-2017-1000256HIGHCVSS 8.1EG 8.12017-10-31
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
- CVE-2017-1000396MEDIUMCVSS 5.9EG 5.92018-01-26
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This libr…
- CVE-2017-1000415MEDIUMCVSS 5.9EG 5.92018-01-09
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.
- CVE-2017-1000417MEDIUMCVSS 5.3EG 5.32018-01-22
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.
- CVE-2017-10620HIGHCVSS 7.4EG 7.42017-10-13
Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make t…
- CVE-2017-10819MEDIUMCVSS 5.9EG 5.92017-08-04
MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communication.
- CVE-2017-11132HIGHCVSS 7.5EG 7.52017-08-01
An issue was discovered in heinekingmedia StashCat before 1.5.18 for Android. No certificate pinning is implemented; therefore the attacker could issue a certificate for the backend and the application would not notice it.
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →