← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Juniper
1Junos
Jun 17, 2026
Oct 9, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos OS allows an attacker to perform Man-in-the-Middle (MitM) attacks which...Show more
An Improper Certificate Validation weakness in the SRX Series Application Identification (app-id) signature update client of Juniper Networks Junos OS allows an attacker to perform Man-in-the-Middle (MitM) attacks which may compromise the integrity and confidentiality of the device. This issue affects: Juniper Networks Junos OS 15.1X49 versions prior to 15.1X49-D120 on SRX Series devices. No other versions of Junos OS are affected.Show less
1Netapp
1Clustered Data Ontap
Jun 17, 2026
Oct 9, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks.
1Twitter
1Twitter Kit
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implement...Show more
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implementation errors such as a lack of hostname verification. NOTE: this is an end-of-life product.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
1Microsoft
1Project Rome
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosure Vulnerability'.
1Couchbase
1Couchbase Server
Jun 17, 2026
Sep 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the certificate signature. It then accepted the invalid certificate and at...Show more
In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the certificate signature. It then accepted the invalid certificate and attempted to use it to establish future connections to the remote cluster. This has been fixed in version 5.5.0. XDCR now checks the validity of the certificate thoroughly and prevents a remote cluster reference from being created with an invalid certificate.Show less
1Limesurvey
1Limesurvey
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.
4Debian
FedoraprojectImapfilter Project+1 more
5Backports Sle
Debian LinuxFedora+2 more
Nov 21, 2024
Sep 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
1Dell
1Emc Enterprise Copy Data Management
Jun 17, 2026
Sep 3, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry...Show more
Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit.Show less
1Security Framework Project
1Security Framework
Nov 21, 2024
Aug 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
1Rust Openssl Project
1Rust Openssl
Nov 21, 2024
Aug 26, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.
1Pw3270 Project
1Pw3270
Jun 17, 2026
Aug 23, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
1Cisco
1Webex Meetings
Jun 17, 2026
Aug 21, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vuln...Show more
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vulnerability is due to insufficient SSL certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted SSL certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.Show less
1Huawei
1Cloudlink Phone 7900 Firmware
Jun 17, 2026
Aug 13, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification of specific parameters of the TLS server certificate, attackers can pe...Show more
The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification of specific parameters of the TLS server certificate, attackers can perform man-in-the-middle attacks, leading to the affected phones registered abnormally, affecting the availability of IP phones.Show less
1Uidai
1Maadhaar
Jun 17, 2026
Aug 13, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The mAadhaar application 1.2.7 for Android lacks SSL Certificate Validation, leading to man-in-the-middle attacks against requests for FAQs or Help.
1Jenkins
1Vmware Lab Manager Slaves
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
1Jenkins
1Codefresh Integration
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
2Gnome
Redhat
2Enterprise Linux
Evolution Ews
Jun 17, 2026
Aug 1, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server witho...Show more
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference.Show less
1Dlink
36600 Ap Firmware
Dwl 3600ap FirmwareDwl 8610ap Firmware
Jun 17, 2026
Aug 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA Private Key extraction through an insecure sslcert-get.cgi HTTP comman...Show more
An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA Private Key extraction through an insecure sslcert-get.cgi HTTP command.Show less