← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Verify Access
Jun 17, 2026
Feb 7, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.
1Ibm
1Security Verify Access
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.
1Rustdesk
1Rustdesk
Jun 17, 2026
Feb 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. T...Show more
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially unwanted, e.g., because there is no public documentation of security measures for the private key, and arbitrary software could be signed if the private key were to be compromised. NOTE: the vendor's position is "we do not have EV cert, so we use test cert as a workaround." Insertion into Trusted Root Certification Authorities was the originally intended behavior, and the UI ensured that the certificate installation step (checked by default) was visible to the user before proceeding with the product installation.Show less
1Hashicorp
1Boundary
Jun 17, 2026
Feb 5, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to...Show more
Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and obtain a valid trust on first use (TOFU) token may craft a TLS certificate to hijack an active session and gain access to the underlying service or application.Show less
1Haxx
1Curl
Jun 17, 2026
Feb 3, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was...Show more
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.Show less
1Dell
2Bsafe Crypto C Micro Edition
Bsafe Micro Edition Suite
Jun 17, 2026
Feb 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Cryptographic Step Vulnerability.
1Zscaler
1Secure Internet And Saas Access
Jun 17, 2026
Jan 31, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traff...Show more
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.Show less
1Areal Topkapi
1Vision Server
Jun 17, 2026
Jan 31, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive...Show more
SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.Show less
1Meshcentral
1Meshcentral
Jun 17, 2026
Jan 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.
1Splicecom
1Maximiser Soft Pbx
Jun 17, 2026
Jan 25, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.
1Splicecom
2Ipcs
Ipcs2
Jun 17, 2026
Jan 25, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle a...Show more
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.Show less
1Lenovo
1Vantage
Jun 17, 2026
Jan 19, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated privileges.
1Cohesity
1Cohesity Dataplatform
Jun 17, 2026
Jan 19, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.
1Snowflake
1Snowflake Connector
Jun 17, 2026
Dec 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET...Show more
The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in version 2.1.5.Show less
1Eset
9Endpoint Antivirus
Endpoint SecurityFile Security+6 more
Jun 17, 2026
Dec 21, 2023
N/A· v4
8.6 HIGH· v3
N/A· v2
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
1Hitachienergy
1Rtu500 Scripting Interface
Jun 17, 2026
Dec 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and...Show more
A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote service can be trusted and is not malicious. If the client does not validate the parameters of the certificate, then attackers could be able to spoof the identity of the service. An attacker could exploit the vulnerability by using faking the identity of a RTU500 device and intercepting the messages initiated via the RTU500 Scripting interface.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 15, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as ano...Show more
An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.Show less
1Jruby
1Jruby Openssl
Nov 21, 2024
Dec 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
1Beyondtrust
1Privilege Management For Windows
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires th...Show more
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires that the certificate is valid). If an Add Admin token is protected by this criteria, it can be leveraged by a malicious actor to achieve Elevation of Privileges from standard user to administrator.Show less
1Siemens
1Sinec Ins
Jun 17, 2026
Dec 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept cred...Show more
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges.Show less