← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Sep 12, 2025
6.3 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.
-
-
Jun 17, 2026
Sep 3, 2025
7.7 HIGH· v4
N/A· v3
N/A· v2
PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to confi...Show more
PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the customer does not fully configure the system to leverage the trust database on the clients, it opens up the communication between clients and the server to man-in-the-middle attacks.  It was discovered that certain parts of the documentation related to the configuration of SSL in Print Deploy were lacking, which could potentially contribute to a misconfiguration of the Print Deploy client installation. PaperCut strongly recommends to use valid certificates to secure installations and to follow the updated documentation to ensure the correct SSL configuration. Those who use private CAs and/or self-signed certificates should make sure to copy their Certification Authority certificate, or their self signed certificate if using only one, to the trust store of their operating system and to the Java key storeShow less
1Ibm
1Concert
Jun 17, 2026
Sep 1, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.
1Qnap
1Qsync Central
Jun 17, 2026
Aug 29, 2025
8.3 HIGH· v4
8.8 HIGH· v3
N/A· v2
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We...Show more
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and laterShow less
1Qnap
1Qsync Central
Jun 17, 2026
Aug 29, 2025
8.3 HIGH· v4
8.8 HIGH· v3
N/A· v2
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We...Show more
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and laterShow less
1Tomtretbar
1Dell Powerscale
Jun 17, 2026
Aug 28, 2025
6.9 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic.
1Tomtretbar
1Vmware Vsan
Jun 17, 2026
Aug 28, 2025
6.9 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic.
1Pawelko
1Freebox V6 Agent
Jun 17, 2026
Aug 28, 2025
6.9 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to intercept traffic.
1Heinlein Support
1Check Mk Python Api
Jun 17, 2026
Aug 28, 2025
6.9 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.
1Oetiker
1Bgp Monitoring
Jun 17, 2026
Aug 28, 2025
6.9 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.
-
-
Jun 17, 2026
Aug 21, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.
1Ibm
1Websphere Application Server
Jun 17, 2026
Aug 14, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
-
-
Jun 17, 2026
Aug 14, 2025
6.0 MEDIUM· v4
N/A· v3
N/A· v2
An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server wi...Show more
An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.Show less
-
-
Jun 17, 2026
Aug 13, 2025
5.3 MEDIUM· v4
N/A· v3
N/A· v2
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating syst...Show more
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.Show less
1F5
1F5 Access
Jun 17, 2026
Aug 13, 2025
8.8 HIGH· v4
7.4 HIGH· v3
N/A· v2
F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
-
-
Jun 17, 2026
Aug 8, 2025
8.5 HIGH· v4
7.3 HIGH· v3
N/A· v2
A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle a...Show more
A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.Show less
-
-
Jun 17, 2026
Aug 6, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provid...Show more
A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite conditions were satisfied. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed due to client certificate validation issues. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by monitoring local wireless or adjacent networks for client-join requests and attempting to interrupt and complete the meeting-join flow as another user who was currently joining a meeting. To successfully exploit the vulnerability, an attacker would need the capability to position themselves in a local wireless or adjacent network, to monitor and intercept the targeted network traffic flows, and to satisfy timing requirements in order to interrupt the meeting-join flow and exploit the vulnerability. A successful exploit could have allowed the attacker to join the meeting as another user. However, the Cisco Product Security Incident Response Team (PSIRT) is not aware of any malicious use of the vulnerability that is described in this advisory.Show less
-
-
Jun 17, 2026
Aug 6, 2025
N/A· v4
5.7 MEDIUM· v3
N/A· v2
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in...Show more
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton G4 PDU which is available on the Eaton download center.Show less
1Checkpoint
1Log Server
Jun 17, 2026
Aug 6, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs
1Huawei
1Harmonyos
Jun 17, 2026
Aug 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.