← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Meetcircle
1Circle With Disney Firmware
May 13, 2026
Nov 7, 2017
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bluecoat library to accept a different certificate than intended. An atta...Show more
An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bluecoat library to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.Show less
2Debian
Redhat
2Debian Linux
Libvirt
May 13, 2026
Oct 31, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 13, 2026
Oct 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allo...Show more
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allows remote attackers to bypass intended certificate-trust restrictions via a revoked X.509 certificate.Show less
1F5
1Big Ip Policy Enforcement Manager
May 13, 2026
Oct 20, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verified. Attackers in a privileged network position may be able to launch a...Show more
In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verified. Attackers in a privileged network position may be able to launch a man-in-the-middle attack against these connections. TAC databases are used in BIG-IP PEM for Device Type and OS (DTOS) and Tethering detection. Customers not using BIG-IP PEM, not configuring downloads of TAC database files, or not using HTTP for that download are not affected.Show less
1Ms Ins
2Sumaho
Sumaho Driving Capability Diagnosis
May 13, 2026
Oct 18, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to spoof servers and obta...Show more
The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to spoof servers and obtain sensitive information by leveraging failure to verify SSL/TLS server certificates.Show less
1Redhat
1Enterprise Mrg
May 13, 2026
Oct 18, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.509 certificates.
2Akeo
Rufus Project
2Rufus
Rufus
May 13, 2026
Oct 18, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code
1Juniper
1Junos
May 13, 2026
Oct 13, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service di...Show more
Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect certain types of attacks. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D55; 15.1X49 prior to 15.1X49-D110;Show less
1Cisco
24Pvc2300 Firmware
Rtp300 FirmwareRv120w Firmware+21 more
May 13, 2026
Oct 12, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attac...Show more
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.Show less
1Gurunavi
1Gournavi
May 13, 2026
Oct 10, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-the-middle attacks.
1Dwango
1Niconico
May 13, 2026
Oct 10, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks.
1Rakutencard
1Rakuten Card
May 13, 2026
Oct 10, 2017
N/A· v4
7.4 HIGH· v3
4.0 MEDIUM· v2
Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to execute man-in-the-middle attacks.
1Golang
1Go
May 13, 2026
Oct 5, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using...Show more
On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.Show less
1Zohocorp
1Site24x7 Mobile Network Poller
May 13, 2026
Sep 30, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information...Show more
The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed certificate.Show less
1Cisco
2Ios
Ios Xe
May 13, 2026
Sep 29, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive dat...Show more
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software. Cisco Bug IDs: CSCvc33171.Show less
1Okb
1Smart Passbook
May 13, 2026
Sep 26, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information from encrypted communications via a crafted certificate.
1Schneider Electric
2Citect Anywhere
Powerscada Anywhere
May 13, 2026
Sep 26, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites a...Show more
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.Show less
1Comicsmart
1Ganma!
May 13, 2026
Sep 25, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
GANMA! App for iOS does not verify SSL certificates.
1Ana
1All Nippon Airways
May 13, 2026
Sep 25, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates.
1Pulpproject
1Pulp
May 13, 2026
Sep 25, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.