CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2023-4801 HIGH
ITM Agent for MacOS <7.14.3.69 - Info Disclosure
CVSS 7.5
CVE-2023-35845 MEDIUM
Anaconda3 2023.03-1-Linux - TLS Certificate Validation Disruption via World-Writable cacert.pem
CVSS 4.7
CVE-2023-30729 HIGH
Samsung Email < 6.1.82.0 - Improper Certificate Validation
CVSS 8.1
CVE-2023-41180 MEDIUM
Apache NiFi MiNiFi C++ <0.15 - Certificate Validation
CVSS 5.9
CVE-2023-39441 MEDIUM
Apache Airflow < 2.7.0 - Improper Certificate Validation
CVSS 5.9
CVE-2023-1409 MEDIUM
MongoDB Server <6.3, 5.0.0-5.0.14, 4.4 - Info Disclosure
CVSS 5.3
CVE-2023-21265 HIGH
Android - Improper Certificate Validation
CVSS 7.5
CVE-2023-40256 CRITICAL
Veritas NetBackup Snapshot Manager < 10.2.0.1 - Improper Certificate Validation in RabbitMQ Service
CVSS 9.8
CVE-2023-38686 CRITICAL
Sydent < 2.5.6 - Improper Certificate Validation in SMTP TLS
CVSS 9.3
CVE-2023-34143 MEDIUM
Hitachi Device Manager <8.8.5-02 - Man in the Middle
CVSS 5.6
CVE-2023-3724 CRITICAL
wolfssl < 5.6.2 - Predictable IKM Value in TLS 1.3 Session Key Generation
CVSS 9.1
CVE-2023-3615 HIGH
Mattermost iOS - SSL/TLS Info Disclosure
CVSS 8.1
CVE-2023-38325 HIGH
Cryptography <41.0.2 - Info Disclosure
CVSS 7.5
CVE-2023-31190 HIGH
DroneScout DS230 Firmware 20211210-1627-20230329-1042 - Improper Certificate Validation in Firmware Update Procedure
CVSS 8.1
CVE-2023-23546 MEDIUM
Milesight UR32L v32.3.0.5 - Improper Certificate Validation in urvpn_client
CVSS 4.2
CVE-2023-33201 MEDIUM
Bouncy Castle For Java <1.74 - LDAP Injection
CVSS 5.3
CVE-2023-32464 LOW
Dell VxRail 7.0.0-7.0.449 - Improper Certificate Validation
CVSS 2.7
CVE-2023-34414 LOW
Firefox < 114.0 and Firefox ESR < 102.12 - Improper Certificate Validation via Clickjacking Bypass
CVSS 3.1
CVE-2023-30222 HIGH
4D Server v17 v18 v19 R7 and earlier - Information Disclosure via Password Hash Eavesdropping
CVSS 7.5
CVE-2023-35142 HIGH
Jenkins Checkmarx Plugin < 2023.4.3 - Improper Certificate Validation
CVSS 8.1
CVE-2023-29501 MEDIUM
Jiyu Kukan Toku-Toku Coupon App < 3.5.0 - Improper Certificate Validation
CVSS 4.8
CVE-2023-29175 MEDIUM
FortiOS and FortiProxy - Man-in-the-Middle via Improper FortiGuard Certificate Validation
CVSS 4.8
CVE-2023-34410 MEDIUM
Debian Linux < 5.15.15 - Improper Certificate Validation
CVSS 5.3
CVE-2023-0547 MEDIUM
Thunderbird 68.0-102.9.1 - Improper Certificate Validation in S/MIME Encrypted Email
CVSS 6.5
CVE-2023-0430 MEDIUM
Thunderbird 68.0-102.7.0 - Improper Certificate Validation for S/MIME Signatures
CVSS 6.5
Details
Vulnerabilities 1,454