← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Adacore
Debian
2Ada Web Server
Debian Linux
Jun 17, 2026
Feb 26, 2025
N/A· v4
7.4 HIGH· v3
N/A· v2
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using...Show more
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).Show less
1Sungrowpower
1Isolarcloud
Jun 17, 2026
Feb 26, 2025
N/A· v4
7.4 HIGH· v3
N/A· v2
SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers can impersonate the iS...Show more
SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers can impersonate the iSolarCloud server and communicate with the Android app.Show less
-
-
Jun 17, 2026
Feb 21, 2025
5.7 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle at...Show more
Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle attack (MITM). An attacker could modify the server's response and deliver a malicious update to the user.Show less
1Ibm
1Openpages With Watson
Jun 17, 2026
Feb 20, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disc...Show more
IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.Show less
1Dell
1Bsafe Ssl J
Jun 17, 2026
Feb 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information di...Show more
Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure.Show less
1Microdicom
1Dicom Viewer
Jun 17, 2026
Feb 10, 2025
5.7 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a ma...Show more
MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.Show less
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
Feb 10, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-...Show more
Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host.Show less
1Devolutions
2Remote Desktop Manager
Remote Desktop Manager Powershell
Jun 17, 2026
Feb 10, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected ar...Show more
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlierShow less
-
-
Jun 17, 2026
Feb 6, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. 2N has currently released an updated version 3.3 of 2N A...Show more
2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. 2N has currently released an updated version 3.3 of 2N Access Commander, with added Certificate Fingerprint Verification. Since version 2.2 of 2N Access Commander (released in February 2022) it is also possible to enforce TLS certificate validation.It is recommended that all customers update 2N Access Commander to the latest version and use one of two mentioned practices.Show less
-
-
Jun 17, 2026
Feb 5, 2025
N/A· v4
9.0 CRITICAL· v3
N/A· v2
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Feb 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbi...Show more
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.Show less
-
-
Jun 17, 2026
Feb 1, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.
1Chargepoint
3Home Flex Hardwired Firmware
Home Flex Nema 14 50 Plug FirmwareHome Flex Nema 6 50 Plug Firmware
Jun 17, 2026
Jan 31, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. T...Show more
This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST setting. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.Show less
1Pioneer
1Dmh Wt7600nex Firmware
Jun 17, 2026
Jan 31, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulner...Show more
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the telematics functionality, which operates over HTTPS. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.Show less
1Ibm
1Cognos Analytics
Jun 17, 2026
Jan 26, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
1Ecovacs
20Deebot T10 Firmware
Deebot T10 Omni FirmwareDeebot T10 Plus Firmware+17 more
Jun 17, 2026
Jan 23, 2025
9.5 CRITICAL· v4
7.4 HIGH· v3
N/A· v2
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
1Ecovacs
1Home
Jun 17, 2026
Jan 23, 2025
9.5 CRITICAL· v4
7.4 HIGH· v3
N/A· v2
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.
-
-
Jun 17, 2026
Jan 23, 2025
N/A· v4
2.8 LOW· v3
N/A· v2
BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handling of SSL certificates validation.
-
-
Jun 17, 2026
Jan 16, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.
-
-
Jun 17, 2026
Jan 15, 2025
7.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.