CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2023-49247 HIGH
Huawei EMUI and HarmonyOS - Permission Verification
CVSS 7.5
CVE-2023-5909 HIGH
KEPServerEX < 6.14.263.0 - Unauthenticated Improper Certificate Validation
CVSS 7.5
CVE-2023-49312 CRITICAL
Precision Bridge <7.3.21 - Info Disclosure
CVSS 9.1
CVE-2023-43082 HIGH
Dell Unity <5.3 - Privilege Escalation
CVSS 8.6
CVE-2023-48054 HIGH
localstack 2.3.2 - Missing SSL Certificate Validation
CVSS 7.4
CVE-2023-48052 HIGH
httpie < 3.2.3 - Missing SSL Certificate Validation
CVSS 7.4
CVE-2023-42532 MEDIUM
Samsung Android FotaAgent - Improper Certificate Validation
CVSS 5.9
CVE-2023-46724 HIGH
Squid 3.3.0.1-5.9 and < 6.4 - Denial of Service via Crafted SSL Certificate in TLS Handshake
CVSS 8.6
CVE-2023-42425 CRITICAL
Turing Edge+ EVC5FD Firmware 1.38.6 - Remote Code Execution and Information Disclosure via Cloud Connection
CVSS 9.8
CVE-2023-21358 HIGH
Android - Local Privilege Escalation via UWB Crypto Masquerade
CVSS 7.8
CVE-2023-31421 MEDIUM
Beats/Elastic Agent/APM Server/Fleet Server - SSL Validation
CVSS 5.9
CVE-2023-31580 MEDIUM
light-oauth2 < 2.1.27 - Improper Certificate Validation
CVSS 5.9
CVE-2023-5422 HIGH
OTRS 6.0.0-6.0.34 and 7.0.0-7.0.46 - Improper Certificate Validation in Email Fetching and Sending
CVSS 8.7
CVE-2023-4499 HIGH
HP ThinUpdate < 2.7.15 - Improper Certificate Validation
CVSS 7.5
CVE-2023-5554 MEDIUM
LINE < 13.16.0 - Improper Certificate Validation in Financial Module Log Transmission
CVSS 4.8
CVE-2023-45613 MEDIUM
JetBrains Ktor < 2.3.5 - Improper Certificate Validation
CVSS 6.8
CVE-2023-4586 HIGH
Red Hat Data Grid Hot Rod Client - Improper Certificate Validation
CVSS 7.4
CVE-2023-2422 MEDIUM
Keycloak < 21.1.2 - Improper Certificate Validation
CVSS 5.5
CVE-2023-41991 MEDIUM KEV
iPadOS < 16.7 and iPhone OS < 16.7 - Certificate Validation Bypass
CVSS 5.5
CVE-2023-38356 HIGH
MiniTool Power Data Recovery 11.6 - RCE
CVSS 8.1
CVE-2023-38355 HIGH
MiniTool Movie Maker 7.0 - Remote Code Execution via Man-in-the-Middle Attack
CVSS 8.1
CVE-2023-38354 HIGH
MiniTool ShadowMaker 4.1 - Remote Code Execution via Man-in-the-Middle Attack
CVSS 8.1
CVE-2023-38353 MEDIUM
MiniTool Power Data Recovery <11.6 - Info Disclosure
CVSS 5.9
CVE-2023-38352 HIGH
MiniTool Partition Wizard 12.8 - RCE
CVSS 8.1
CVE-2023-38351 HIGH
MiniTool Partition Wizard 12.8 - RCE
CVSS 8.1
Details
Vulnerabilities 1,454