CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 4R8900 Firmware R9000 FirmwareRax120 Firmware+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 15, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 IBM QRadar 7.3.0 to 7.3.3 Patch 2 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-ForceID: 170965. |
1Mongodb 1Mongodb Enterprise Kubernetes Operator Jun 17, 2026 Apr 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication,...Show more |
1Pulsesecure 2Pulse Connect Secure Pulse Policy SecureJun 17, 2026 Apr 6, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SS...Show more |
2Apache Oracle2Graalvm NetbeansJun 17, 2026 Mar 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injec...Show more |
1Dell 2Emc Data Protection Central Emc Integrated Data Protection ApplianceJun 17, 2026 Mar 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining...Show more |
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate for asustornasapi.asustor.com. In other words, there is Missing SSL Cer...Show more |
1Entrustdatacard 1Entelligence Security Provider Jun 17, 2026 Mar 18, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has...Show more |
4Debian FedoraprojectGolang+1 more4Cloud Insights Telegraf Debian LinuxFedora+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate. |
1Citrix 2Citrix Sd Wan Center Netscaler Sd Wan CenterJun 17, 2026 Mar 16, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. |
1Traefik 2Traefik Traefik EnterpriseJun 17, 2026 Mar 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging. |
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cl...Show more |
Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust. |
2Debian Gnome2Debian Linux NetworkmanagerNov 21, 2024 Mar 10, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection. |
Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using a self-signed certifi...Show more |
1Cisco 8Intelligence Proximity JabberMeeting+5 moreJun 17, 2026 Mar 4, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alter information shared on Cisco Webex video devices and Cisco collaborati...Show more |
1Lua Openssl Project 1Lua Openssl Jun 17, 2026 Feb 27, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. |
1Lua Openssl Project 1Lua Openssl Jun 17, 2026 Feb 27, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. |
1Lua Openssl Project 1Lua Openssl Jun 17, 2026 Feb 27, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. |
3Fedoraproject Openfortivpn ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.examp...Show more |