CWE-296
14 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-296page 1 of 1
- CVE-2019-3762HIGHCVSS 7.5EG 7.52020-03-18
Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certif…
- CVE-2019-3890HIGHCVSS 8.1EG 8.12019-08-01
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticin…
- CVE-2021-1566HIGHCVSS 7.4EG 7.42021-06-16
A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to in…
- CVE-2021-23155CRITICALCVSS 9.0EG 6.82021-11-18
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions p…
- CVE-2021-23162HIGHCVSS 7.7EG 7.72021-11-18
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions p…
- CVE-2021-44532MEDIUMCVSS 5.3EG 5.32022-02-24
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject…
- CVE-2024-43196MEDIUMCVSS 4.3EG 4.32025-02-20
IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof other users' responses.
- CVE-2025-10539MEDIUMCVSS 4.8EG 4.82026-04-28
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious execut…
- CVE-2025-1146HIGHCVSS 8.1EG 8.12025-02-12
CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernet…
- CVE-2025-22459MEDIUMCVSS 4.8EG 4.82025-04-08
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.
- CVE-2025-48057CRITICALCVSS 9.8EG 9.82025-05-27
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function c…
- CVE-2026-33779MEDIUMCVSS 6.5EG 6.52026-04-09
An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential information and potentially…
- CVE-2026-42789HIGHCVSS 7.0EG 7.02026-05-27
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key/s…
- CVE-2026-44852HIGHCVSS 7.2EG 7.22026-05-12
An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitra…
Map vulnerabilities like CWE-296 to your infrastructure
EchelonGraph correlates every CVE — across CWE-296 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →