CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,455 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 4 of 30
- CVE-2017-11364HIGHCVSS 8.8EG 8.82017-08-02
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
- CVE-2017-11501MEDIUMCVSS 5.9EG 5.92017-07-20
NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. It was found that if TLS is enabled to conn…
- CVE-2017-11506HIGHCVSS 7.4EG 7.42017-08-09
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.
- CVE-2017-11770HIGHCVSS 7.5EG 7.52017-11-15
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core …
- CVE-2017-1200MEDIUMCVSS 3.7EG 5.92019-02-05
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The softwa…
- CVE-2017-12195MEDIUMCVSS 6.5EG 6.52018-07-27
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing aut…
- CVE-2017-12228MEDIUMCVSS 5.9EG 5.92017-09-29
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an inval…
- CVE-2017-1265MEDIUMCVSS 3.7EG 5.92018-12-17
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) tech…
- CVE-2017-12721MEDIUMCVSS 5.9EG 5.92018-02-15
An Improper Certificate Validation issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump does not validate host certificates, leaving the pump vulnerable to a man-in-the-m…
- CVE-2017-13083HIGHCVSS 8.1EG 8.12017-10-18
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code
- CVE-2017-13105MEDIUMCVSS 5.9EG 5.92018-08-15
Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates during SSL communication. This opens the application up to a man-in-the-middle attack having all of its encrypted traf…
- CVE-2017-13863MEDIUMCVSS 5.9EG 5.92018-04-03
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "APNs" component. It allows man-in-the-middle attackers to track users by leveraging the transmission of client certificates.
- CVE-2017-14419MEDIUMCVSS 5.9EG 5.92017-09-13
The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, participates in mydlink Cloud Services by establishing a TCP relay service f…
- CVE-2017-14420MEDIUMCVSS 5.9EG 5.92017-09-13
The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, does not verify X.509 certificates from SSL servers, which allows man-in-the…
- CVE-2017-14582MEDIUMCVSS 5.9EG 5.92017-09-30
The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed …
- CVE-2017-14612MEDIUMCVSS 5.9EG 5.92018-07-12
"Shpock Boot Sale & Classifieds" app before 3.17.0 -- aka shpock-boot-sale-classifieds/id557153158 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensiti…
- CVE-2017-14709HIGHCVSS 7.4EG 7.42018-07-12
The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and o…
- CVE-2017-14710MEDIUMCVSS 5.9EG 5.92018-07-12
The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive in…
- CVE-2017-14806LOWCVSS 3.7EG 3.72020-01-27
A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the repositories, which allows the modification of packages received over these connections. This iss…
- CVE-2017-15114HIGHCVSS 8.1EG 8.12017-11-27
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these servi…
- CVE-2017-15341HIGHCVSS 7.5EG 7.52018-02-15
Huawei AR3200 V200R008C20, V200R008C30, TE40 V600R006C00, TE50 V600R006C00, TE60 V600R006C00 have a denial of service vulnerability. The software decodes X.509 certificate in an improper way. A remote unauthenticated attacker could send a …
- CVE-2017-15528LOWCVSS 3.7EG 3.72017-11-22
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain na…
- CVE-2017-15698MEDIUMCVSS 5.9EG 5.92018-01-31
When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP c…
- CVE-2017-1622HIGHCVSS 3.7EG 7.42018-12-05
IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-force ID: 133120.
- CVE-2017-17301CRITICALCVSS 9.8EG 9.82018-02-15
Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR1200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR150 V200R00…
- CVE-2017-17455MEDIUMCVSS 5.9EG 5.92018-02-20
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is pres…
- CVE-2017-17716MEDIUMCVSS 5.9EG 5.92017-12-17
GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of t…
- CVE-2017-17718MEDIUMCVSS 5.9EG 5.92017-12-17
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.
- CVE-2017-17944CRITICALCVSS 9.1EG 9.12019-06-20
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
- CVE-2017-17945CRITICALCVSS 9.1EG 9.12019-06-24
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
- CVE-2017-18227HIGHCVSS 7.5EG 7.52018-03-12
TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature.
- CVE-2017-18479MEDIUMCVSS 6.5EG 6.52019-08-05
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
- CVE-2017-18588MEDIUMCVSS 5.3EG 5.32019-08-26
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
- CVE-2017-18909HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
- CVE-2017-18911CRITICALCVSS 9.1EG 9.12020-06-19
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
- CVE-2017-18918MEDIUMCVSS 4.9EG 4.92020-06-19
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
- CVE-2017-2110MEDIUMCVSS 5.9EG 5.92017-04-28
The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi…
- CVE-2017-2278MEDIUMCVSS 5.9EG 5.92017-08-02
The RBB SPEED TEST App for Android version 2.0.3 and earlier, RBB SPEED TEST App for iOS version 2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain se…
- CVE-2017-2299HIGHCVSS 7.5EG 7.52017-09-15
Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_ca` parameter but do not specify the `ssl_certs_dir` parameter, a default will be provided…
- CVE-2017-2387MEDIUMCVSS 4.8EG 4.82017-04-07
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted …
- CVE-2017-2498HIGHCVSS 7.5EG 7.52017-05-22
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Security" component. It allows attackers to bypass intended access restrictions via an untrusted certificate.
- CVE-2017-2623MEDIUMCVSS 5.3EG 5.32018-07-27
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue i…
- CVE-2017-2629MEDIUMCVSS 4.3EG 6.52018-07-27
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there…
- CVE-2017-2639HIGHCVSS 6.5EG 7.52018-07-27
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spo…
- CVE-2017-2648MEDIUMCVSS 6.8EG 6.82018-07-27
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
- CVE-2017-2649HIGHCVSS 8.1EG 8.12018-07-27
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
- CVE-2017-2667HIGHCVSS 8.1EG 8.12018-03-12
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-i…
- CVE-2017-2784HIGHCVSS 8.1EG 8.12017-04-20
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library…
- CVE-2017-2800CRITICALCVSS 9.8EG 9.82017-05-24
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to…
- CVE-2017-2836MEDIUMCVSS 5.9EG 5.92018-04-24
An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of ser…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →