← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
Jul 9, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently...Show more
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.Show less
1Traefik
1Traefik
Jun 17, 2026
Jul 2, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH_CERT should have occurred.
1F5
1Nginx Controller
Jun 17, 2026
Jul 2, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
1Trojita Project
1Trojita
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
1Dell
3Emc Unisphere For Powermax
Emc Unisphere For Powermax Virtual AppliancePowermax Os
Jun 17, 2026
Jun 23, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerabil...Show more
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim's data in transit.Show less
1Vipre
1Password Vault
Jun 17, 2026
Jun 22, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
1Sophos
1Sophos Secure Email
Jun 17, 2026
Jun 22, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
1Cisco
1Webex Meetings
Jun 17, 2026
Jun 18, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability is due to impr...Show more
A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability is due to improper validation of cryptographic protections on files that are downloaded by the application as part of a software update. An attacker could exploit this vulnerability by persuading a user to go to a website that returns files to the client that are similar to files that are returned from a valid Webex website. The client may fail to properly validate the cryptographic protections of the provided files before executing them as part of an update. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the user.Show less
1Ibm
1Mq
Jun 17, 2026
Jun 16, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.
1Nutfind
1Nutfind
Jun 17, 2026
Jun 12, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Jun 10, 2020
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area ne...Show more
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipulate ARP or to conduct ARP spoofing attacks. This allows the attacker to access the GlobalProtect Server as allowed by configured Security rules for the 'pre-login' user. This access may be limited compared to the network access of regular users. This issue affects: GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 when the prelogon feature is enabled; GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 when the prelogon feature is enabled.Show less
1Google
1Android
Jun 17, 2026
Jun 10, 2020
N/A· v4
5.3 MEDIUM· v3
5.4 MEDIUM· v2
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no...Show more
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150500247Show less
1Couchbase
1Couchbase Server Java Sdk
Jun 17, 2026
Jun 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that wi...Show more
Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing hostname verification.Show less
2Nodejs
Oracle
5Banking Extensibility Workbench
Blockchain PlatformGraalvm+2 more
Jun 17, 2026
Jun 8, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
6Canonical
DebianDjangoproject+3 more
7Debian Linux
DjangoFedora+4 more
Jun 17, 2026
Jun 3, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential da...Show more
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.Show less
1Netgear
14R6120 Firmware
R6220 FirmwareR6350 Firmware+11 more
Jun 17, 2026
May 28, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR...Show more
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.Show less