← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 20, 2021
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests....Show more
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate validation when establishing HTTPS requests with the affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Docker
1Docker
Jun 17, 2026
Jan 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
2Erlang
Fedoraproject
2Erlang/otp
Fedora
Jun 17, 2026
Jan 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.
1Sass Lang
1Node Sass
Jun 17, 2026
Jan 11, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
1Redhat
1Jboss Core Services Httpd
Jun 17, 2026
Jan 7, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopp...Show more
A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.Show less
1Ptarmigan Project
1Ptarmigan
Jun 17, 2026
Dec 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code block.
1Backblaze
1Backblaze
Jun 17, 2026
Dec 27, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disable...Show more
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.Show less
1Nec
1Ism Server
Jun 17, 2026
Dec 24, 2020
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encry...Show more
iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.Show less
1Icinga
1Icinga
Jun 17, 2026
Dec 15, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
8Apple
DebianFedoraproject+5 more
17Clustered Data Ontap
Communications Billing And Revenue ManagementCommunications Cloud Native Core Policy+14 more
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
1Canonical
1Software Properties
Nov 21, 2024
Dec 2, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only check...Show more
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only checked certificates under python3 if a valid certificate bundle was provided. Fixed in software-properties version 0.92.Show less
1Tesla
1Model X Firmware
Jun 17, 2026
Nov 30, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise...Show more
Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise able to send data over the CAN bus) to start and drive the vehicle with a spoofed key fob.Show less
1Primekey
1Ejbca
Jun 17, 2026
Nov 19, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the restriction of client...Show more
An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the restriction of client certificates (for the RA, not the end user) to a limited set of allowed CAs, thus restricting the accessibility of that RA to the rights it has within a specific role. While this works for other protocols such as CMP, it was found that the EJBCA enrollment over an EST implementation bypasses this check, allowing enrollment with a valid client certificate through any functioning and authenticated RA connected to the CA. NOTE: an attacker must already have a trusted client certificate and authorization to enroll against the targeted CA.Show less
1Nextcloud
1Social
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.
3Fedoraproject
GolangNetapp
4Cloud Insights Telegraf Agent
FedoraGo+1 more
Jun 17, 2026
Nov 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
1Synopsys
1Hub Rest Api Python
Jun 17, 2026
Nov 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
1Synology
1Router Manager
Jun 17, 2026
Oct 29, 2020
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif...Show more
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Synology
2Diskstation Manager
Skynas Firmware
Jun 17, 2026
Oct 29, 2020
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte...Show more
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Apple
3Iphone Os
Mac Os XWatchos
Jun 17, 2026
Oct 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 20...Show more
A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An untrusted radius server certificate may be trusted.Show less
1Apple
1Mac Os X
Jun 17, 2026
Oct 27, 2020
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
An issue existed in the handling of S-MIME certificates. This issue was addressed with improved validation of S-MIME certificates. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Securi...Show more
An issue existed in the handling of S-MIME certificates. This issue was addressed with improved validation of S-MIME certificates. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.Show less