← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
Openfortivpn ProjectOpensuse
4Backports Sle
FedoraLeap+1 more
Jun 17, 2026
Feb 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid ce...Show more
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).Show less
3Fedoraproject
Openfortivpn ProjectOpensuse
4Backports Sle
FedoraLeap+1 more
Jun 17, 2026
Feb 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.
1Puppet
2Puppet
Puppet Agent
Jun 17, 2026
Feb 19, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node...Show more
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 and 5.5.19 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet Open Source and Puppet Enterprise users that are not upgrading still set strict_hostname_checking to true to ensure secure behavior. Affected software versions: Puppet 6.x prior to 6.13.0 Puppet Agent 6.x prior to 6.13.0 Puppet 5.5.x prior to 5.5.19 Puppet Agent 5.5.x prior to 5.5.19 Resolved in: Puppet 6.13.0 Puppet Agent 6.13.0 Puppet 5.5.19 Puppet Agent 5.5.19Show less
1Globalpayments
1Php Sdk
Jun 17, 2026
Feb 14, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
5Debian
NodejsOpensuse+2 more
10Communications Cloud Native Core Network Function Cloud Native Environment
Debian LinuxEnterprise Linux+7 more
Jun 17, 2026
Feb 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
1Hashicorp
1Nomad
Jun 17, 2026
Jan 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
1Fujixerox
1Apeosware Management Suite
Jun 17, 2026
Jan 31, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a...Show more
The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
1Lwp\
1\
Nov 21, 2024
Jan 28, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_...Show more
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.Show less
977bank
AshikagabankHokkaidobank+6 more
977 Bank
AshiginDogin+6 more
Jun 17, 2026
Jan 28, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man...Show more
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
3Debian
GnuRedhat
3Debian Linux
Enterprise LinuxGnutls
Nov 21, 2024
Jan 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
3Gnome
OpensuseSuse
4Linux Enterprise Desktop
Linux Enterprise ServerNetworkmanager+1 more
Nov 21, 2024
Jan 27, 2020
N/A· v4
6.8 MEDIUM· v3
3.2 LOW· v2
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
1Fujixerox
1Easy Netprint
Jun 17, 2026
Jan 27, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Fujixerox
1Easy Netprint
Jun 17, 2026
Jan 27, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Fujixerox
1Netprint
Jun 17, 2026
Jan 27, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Suse
2Studio Onsite
Susestudio Ui Server
Nov 21, 2024
Jan 27, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the repositories, which allows the modification of packages received over these co...Show more
A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the repositories, which allows the modification of packages received over these connections. This issue affects: SUSE Studio onsite susestudio-common version 1.3.17-56.6.3 and prior versions.Show less
1Mozilla
1Firefox
Nov 21, 2024
Jan 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
1Vmware
9Workspace One Boxer
Workspace One ContentWorkspace One Intelligent Hub+6 more
Jun 17, 2026
Jan 17, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
1Apache
1Beam
Jun 17, 2026
Jan 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in...Show more
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets registered globally which disables trust checking for any code running in the same JVM.Show less
1Cisco
1Ironport Web Security Appliance
Nov 21, 2024
Jan 15, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks