CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU deni...Show more |
1Powermanager 1Kt Mc01507l Z Wave S0 Firmware Nov 21, 2024 Dec 9, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server > Controller (HUB) > Node (products which are controlled by HUB). The pr...Show more |
IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-force ID: 133120...Show more |
4Kddi Ntt TocomoNtttocomo+1 more4+ Message + Message+ Message+1 moreNov 21, 2024 Nov 15, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Messa...Show more |
The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes prev...Show more |
2Microsoft Sennheiser9Headsetup Windows 10Windows 7+6 moreNov 21, 2024 Nov 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software dis...Show more |
1F5 1Big Ip Access Policy Manager Nov 21, 2024 Oct 31, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to downl...Show more |
1Polycom 3Unified Communications Software Vvx 500 FirmwareVvx 601 FirmwareNov 21, 2024 Oct 24, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise inst...Show more |
1Audiocodes 2440hd Firmware 450hd FirmwareNov 21, 2024 Oct 24, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise inst...Show more |
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacke...Show more |
1Cisco 5Vedge 1000 Firmware Vedge 100 FirmwareVedge 2000 Firmware+2 moreNov 21, 2024 Oct 5, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulne...Show more |
1Opcfoundation 2Ua .net Legacy Ua .netstandardNov 21, 2024 Oct 3, 2018 N/A· v4 5.3 MEDIUM· v3 2.1 LOW· v2 Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords. |
IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software mig...Show more |
An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error if the certificate is not valid. Unfortunately, the associated HTTPS request data i...Show more |
2Pivotal Software Vmware2Rabbitmq Java Client Spring Advanced Message Queuing ProtocolMar 27, 2025 Sep 14, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic w...Show more |
1Microsoft 2C Software Development Kit Java Software Development KitJun 17, 2026 Sep 13, 2018 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK. |
The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to obtain interaction data. |
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack. |
2Apache Oracle3Activemq Enterprise RepositoryFlexcube Private BankingNov 21, 2024 Sep 10, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ serv...Show more |
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a...Show more |