CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2023-22943 MEDIUM
Splunk AoB <4.1.2 & Splunk CloudConnect SDK <3.1.3 - Info Disclosure
CVSS 4.8
CVE-2023-22367 MEDIUM
Ichiran App < 3.1.0 - Improper Certificate Validation
CVSS 5.9
CVE-2023-23131 HIGH
Selfwealth iOS App 3.3.1 - Improper Certificate Validation
CVSS 7.5
CVE-2023-0509 HIGH
pyload < 0.5.0b3.dev44 - Improper Certificate Validation
CVSS 7.4
CVE-2023-23690 HIGH
Cloud Mobility for Dell EMC Storage <1.3.0.X - Improper Check for C...
CVSS 7.0
CVE-2022-40620 HIGH
NETGEAR Orbi and Router Firmware - Remote Code Execution via FunJSQ Auto-Update TLS Certificate Validation Bypass
CVSS 7.7
CVE-2022-20814 HIGH
Cisco TelePresence Video Communication Server - Improper Certificate Validation
CVSS 7.4
CVE-2022-45856 MEDIUM
FortiClient 5.0-7.2.1, 6.4-7.2.5, 6.4-7.0.8, 2.0-7.0.7 - Unauthenticated MitM via SAML SSO
CVSS 4.8
CVE-2022-32509 HIGH
Nuki Home Solutions <3.3.5-2.13.2 - Info Disclosure
CVSS 8.8
CVE-2022-3761 MEDIUM
OpenVPN Connect < 3.4.0.4506 (macOS) and < 3.4.0.3100 (Windows) - Improper Certificate Validation
CVSS 5.9
CVE-2022-43892 LOW
IBM Security Verify Privilege On-Premises <11.5 - Info Disclosure
CVSS 3.7
CVE-2022-22380 MEDIUM
IBM Security Verify Privilege On-Premises <11.5 - Spoofing
CVSS 5.0
CVE-2022-22305 MEDIUM
FortiManager <7.0.1, FortiAnalyzer <7.0.2, FortiOS <6.4, FortiSandb...
CVSS 5.4
CVE-2022-45458 HIGH
Acronis Agent < 29633 & Cyber Protect 15 < 30984 - Info Disclosure & Manipulation via Cert Validation
CVSS 7.5
CVE-2022-45457 HIGH
Acronis Agent < 29633 & Cyber Protect 15 < 30984 - Sensitive Info Disclosure via Improper Cert Validation
CVSS 7.5
CVE-2022-39161 MEDIUM
IBM WebSphere Application Server 7.0-9.0 & Liberty - Authenticated Spoofing via Improper Certificate Validation
CVSS 4.8
CVE-2022-35898 CRITICAL
OpenText BizManager <16.6.0.1 - Privilege Escalation
CVSS 9.8
CVE-2022-48186 MEDIUM
Lenovo Baiying < 1.1.4 - Improper Certificate Validation
CVSS 6.2
CVE-2022-47758 CRITICAL
Nanoleaf Firmware <= 7.1.1 - Remote Code Execution via DNS Hijacking
CVSS 9.8
CVE-2022-48437 MEDIUM
LibreSSL < 3.6.1 and OpenBSD < 7.2 - Improper Certificate Validation in x509_verify_ctx_add_chain
CVSS 5.3
CVE-2022-27644 HIGH
NETGEAR Multiple Router Firmware - Improper Certificate Validation
CVSS 8.8
CVE-2022-45597 CRITICAL
ComponentSpace SAML 4.4.0 - Improper Certificate Validation
CVSS 9.8
CVE-2022-4895 HIGH
Hitachi Infrastructure Analytics Advisor <4.4.0 - Man in the Middle...
CVSS 8.6
CVE-2022-39948 MEDIUM
FortiOS 6.0.0-7.0.7 and FortiProxy 1.2.0-2.0.8 - Unauthenticated Man-in-the-Middle via Improper Certificate Validation
CVSS 4.8
CVE-2022-48308 MEDIUM
Palantir sls-logging - SSL/TLS Man-in-the-Middle
CVSS 6.3
Details
Vulnerabilities 1,454