← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zammad
1Zammad
Jun 17, 2026
Dec 10, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable b...Show more
An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Dec 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
KeepserverexKepserver Enterprise+5 more
Jun 17, 2026
Nov 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
1Precisionbridge
1Precision Bridge
Jun 17, 2026
Nov 26, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error...Show more
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address.Show less
1Dell
3Unity Operating Environment
Unity Xt Operating EnvironmentUnityvsa Operating Environment
Jun 17, 2026
Nov 22, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by a...Show more
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate. Show less
1Localstack
1Localstack
Jun 17, 2026
Nov 16, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
1Httpie
1Httpie
Jun 17, 2026
Nov 16, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
1Samsung
1Android
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
1Squid Cache
1Squid
Jun 17, 2026
Nov 1, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service at...Show more
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.Show less
1Turing
1Edge+ Evc5fd Firmware
Jul 9, 2026
Oct 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.
1Google
1Android
Jun 17, 2026
Oct 30, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional executio...Show more
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
1Elastic
4Apm Server
Elastic AgentElastic Beats+1 more
Jun 17, 2026
Oct 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature valid...Show more
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.Show less
1Networknt
1Light Oauth2
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.
1Openvpn
1Connect
Jun 17, 2026
Oct 17, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credenti...Show more
OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credentialsShow less
1Ibm
1Security Verify Privilege On Premises
Jun 17, 2026
Oct 17, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID:...Show more
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID: 240455. Show less
1Ibm
1Security Verify Privilege On Premises
Jun 17, 2026
Oct 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957.
1Otrs
1Otrs
Jun 17, 2026
Oct 16, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted al...Show more
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34. Show less
1Hp
1Thinupdate
Jun 17, 2026
Oct 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for th...Show more
A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.Show less
1Linecorp
1Line
Jun 17, 2026
Oct 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
1Jetbrains
1Ktor
Jun 17, 2026
Oct 9, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In JetBrains Ktor before 2.3.5 server certificates were not verified