CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature. |
The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Missing SSL Certificate Validation issue because no proxy_ssl_* directive...Show more |
1Schneider Electric 20Ibp1110 1er Firmware Ibp219 1er FirmwareIbp319 1er Firmware+17 moreJun 17, 2026 Mar 9, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate. |
2Microfocus Netiq2Edirectory EdirectoryNov 21, 2024 Mar 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server. |
2Elinks Twibright2Elinks LinksNov 21, 2024 Feb 23, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation. |
LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL...Show more |
1Huawei 28Ar120 S Firmware Ar1200 S FirmwareAr1200 Firmware+25 moreNov 21, 2024 Feb 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR1200-S V200R005C32, V200R006C10, V200R007C00, V200R00...Show more |
1Huawei 4Ar3200 Firmware Te40 FirmwareTe50 Firmware+1 moreNov 21, 2024 Feb 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Huawei AR3200 V200R008C20, V200R008C30, TE40 V600R006C00, TE50 V600R006C00, TE60 V600R006C00 have a denial of service vulnerability. The software decodes X.509 certificate in an improper way. A remote unauthenticated att...Show more |
1Smiths Medical 1Medfusion 4000 Wireless Syringe Infusion Pump Nov 21, 2024 Feb 15, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An Improper Certificate Validation issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump does not validate host certificates, leaving the pump vulnerabl...Show more |
1Schneider Electric 1Igss Mobile Nov 21, 2024 Feb 12, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certificate pinning during the TLS/SSL connection establishing process can resul...Show more |
VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information, and consequently execute arbitrary code, v...Show more |
1Pulsesecure 1Desktop Linux Client Jun 17, 2026 Jan 31, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse C...Show more |
2Apache Debian2Debian Linux Tomcat NativeNov 21, 2024 Jan 31, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was...Show more |
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle...Show more |
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates. |
A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did...Show more |
1F5 1Big Ip Advanced Firewall Manager Nov 21, 2024 Jan 19, 2018 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 X509 certificate verification was not correctly implemented in the early access "user id" feature in the F5 BIG-IP Advanced Firewall Manager versions 13.0.0, 12.1.0-12.1.2, and 11.6.0-11.6.2, and thus did not properly va...Show more |
The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate. |
The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |