← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Mozilla
Siemens
9Network Security Services
Ruggedcom Rox Mx5000 FirmwareRuggedcom Rox Rx1400 Firmware+6 more
Jun 17, 2026
Oct 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
1Apple
5Ipados
Iphone OsMac Os X+2 more
Jun 17, 2026
Oct 22, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.1...Show more
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been able to impersonate a trusted website using shared key material for an administrator added certificate.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Oct 21, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vul...Show more
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by sending a crafted data stream to the host input daemon of the affected device. A successful exploit could allow the attacker to cause the host input daemon to restart. The attacker could use repeated attacks to cause the daemon to continuously reload, creating a DoS condition for the API.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Oct 20, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A maliciou...Show more
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is used to download vCenter updates.Show less
1Juniper
1Mist Cloud Ui
Jun 17, 2026
Oct 16, 2020
N/A· v4
8.3 HIGH· v3
4.3 MEDIUM· v2
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could allow a malicious network-based user to a...Show more
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could allow a malicious network-based user to access unauthorized data. This issue affects all Juniper Networks Mist Cloud UI versions prior to September 2 2020.Show less
1Apache
1Calcite
Jun 17, 2026
Oct 9, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connect with Druid and Splu...Show more
HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connect with Druid and Splunk so information leakage may happen when using the respective Calcite adapters. The method itself is in a utility class so people may use it to create vulnerable HTTPS connections for other applications. From Apache Calcite 1.26 onwards, the hostname verification will be performed using the default JVM truststore.Show less
3Debian
OpensuseTigervnc
3Debian Linux
LeapTigervnc
Jun 17, 2026
Sep 27, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could imperso...Show more
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.Show less
1Oauth Ruby Project
1Oauth Ruby
Nov 21, 2024
Sep 24, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain s...Show more
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.Show less
1Trendmicro
5Antivirus+ 2019
Internet Security 2019Maximum Security 2019+2 more
Jun 17, 2026
Sep 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an aff...Show more
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in the communication with the update server.Show less
1Trendmicro
5Antivirus+ 2019
Internet Security 2019Maximum Security 2019+2 more
Jun 17, 2026
Sep 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an aff...Show more
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files are not properly verified.Show less
1Ibm
1Security Secret Server
Jun 17, 2026
Sep 23, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180.
1Meltytech
1Shotcut
Jun 17, 2026
Sep 22, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.
1Bosch
1Smart Home
Jun 17, 2026
Sep 16, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.
1Jenkins
1Email Extension
Jun 17, 2026
Sep 16, 2020
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured SMTP server.
1Jenkins
1Mailer
Jun 17, 2026
Sep 16, 2020
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
1Primekey
1Ejbca
Jun 17, 2026
Sep 11, 2020
N/A· v4
7.3 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certificate. This vulnerability can only affec...Show more
An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certificate. This vulnerability can only affect a system that has EST configured, uses client certificates to authenticate enrollment, and has had such a certificate revoked. This certificate needs to belong to a role that is authorized to enroll new end entities. (To completely mitigate this problem prior to upgrade, remove any revoked client certificates from their respective roles.)Show less
1Qnap
1Helpdesk
Nov 21, 2024
Sep 11, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the commun...Show more
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.Show less
2Philips
Thomsonstb
2Dtr3502bfta Dvb T2 Firmware
Tht741fta Firmware
Jun 17, 2026
Aug 31, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data deliver...Show more
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.Show less
1Scalyr
1Scalyr Agent
Jun 17, 2026
Aug 27, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltName.
1Scalyr
1Scalyr Agent
Jun 17, 2026
Aug 27, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option.