CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2023-50315 MEDIUM
IBM WebSphere Application Server 8.5 and 9.0 - Improper Certificate Validation
CVSS 5.3
CVE-2023-50179 MEDIUM
FortiADC 7.0.0-7.4.0 - Unauthenticated Man-in-the-Middle via Improper Certificate Validation
CVSS 4.8
CVE-2023-50178 HIGH
FortiADC 6.0-6.0.3, 6.1, 6.2, 7.0, 7.1, 7.2.0-7.2.3, 7.4.0 - MITM via Improper Certificate Validation
CVSS 7.4
CVE-2023-35721 HIGH
NETGEAR RAX50 Firmware < 1.0.15.128 - Unauthenticated Remote Code Execution via Improper Certificate Validation
CVSS 8.8
CVE-2023-50949 MEDIUM
IBM QRadar SIEM 7.5 - Improper Certificate Validation
CVSS 5.9
CVE-2023-47742 MEDIUM
IBM Cloud Pak for Security 1.10.0.0-1.10.11.0 and QRadar Suite 1.10.12.0-1.10.18.0 - Improper Certificate Validation
CVSS 5.9
CVE-2023-49250 HIGH
Apache DolphinScheduler <3.2.0 - SSRF
CVSS 7.3
CVE-2023-40104 HIGH
Android - Remote Information Disclosure via Untrusted Cryptographic Certificates
CVSS 7.5
CVE-2023-47537 MEDIUM
FortiOS 7.0.0-7.0.15, 7.2.0-7.2.6, 7.4.0-7.4.1 - Unauthenticated Man-in-the-Middle via FortiLink Certificate Validation
CVSS 4.8
CVE-2023-47700 MEDIUM
IBM Storage Virtualize 8.6 - Improper Certificate Validation
CVSS 5.9
CVE-2023-43017 HIGH
IBM Security Verify Access <10.0.6.1 - Privilege Escalation
CVSS 8.2
CVE-2023-32330 HIGH
IBM Security Verify Access 10.0.0.0-10.0.6.1 - Improper Certificate Validation
CVSS 7.5
CVE-2023-28807 MEDIUM
Zscaler Internet Access < 6.2r.290 - Improper Certificate Validation via SNI Mismatch
CVSS 5.1
CVE-2023-50356 MEDIUM
AREAL Topkapi Vision Server < 6.2.4719 - Improper Certificate Validation
CVSS 6.5
CVE-2023-51837 CRITICAL
Ylianst MeshCentral 1.1.16 - Info Disclosure
CVSS 9.8
CVE-2023-33760 MEDIUM
SpliceCom Maximiser Soft PBX <1.5 - Info Disclosure
CVSS 5.3
CVE-2023-33757 MEDIUM
Splicecom iPCS <v2.8 - Info Disclosure
CVSS 5.9
CVE-2023-6043 HIGH
Lenovo Vantage - Privilege Escalation
CVSS 7.8
CVE-2023-33295 MEDIUM
Cohesity DataProtect <6.8.1_u5-7.1 - Info Disclosure
CVSS 6.5
CVE-2023-51662 MEDIUM
Snowflake .NET <2.1.4 - Info Disclosure
CVSS 6.0
CVE-2023-5594 HIGH
ESET Endpoint Antivirus and Server Security - Improper Certificate Validation in Secure Traffic Scanning
CVSS 7.5
CVE-2023-1514 HIGH
RTU500 Scripting interface - Info Disclosure
CVSS 7.4
CVE-2023-6680 HIGH
GitLab 11.6-16.4.3, 16.5-16.5.3, 16.6-16.6.1 - Improper Certificate Validation in Smartcard Authentication
CVSS 7.4
CVE-2023-48427 HIGH
SINEC INS < V1.0 SP2 Update 2 - Privilege Escalation
CVSS 8.1
CVE-2023-50454 MEDIUM
Zammad < 6.2.0 - Improper Certificate Validation
CVSS 5.9
Details
Vulnerabilities 1,454