The product does not validate, or incorrectly validates, a certificate.
1,400 vulnerabilities with CWE-295
CVE-2020-36477
MEDIUM
Mbed TLS < 2.24.0 - Improper Certificate Validation via SubjectAltName Extension
CVSS 5.9
CVE-2020-12681
HIGH
3xLogic Infinias eIDC32 <3.4.125 - Info Disclosure
CVSS 7.5
CVE-2020-36425
MEDIUM
Arm Mbed TLS < 2.24.0 - Improper Certificate Validation via CRL RevocationDate Check
CVSS 5.3
CVE-2020-15732
MEDIUM
Bitdefender Antivirus/Internet/Total Security <25.0.7.29 - Improper Certificate Validation
CVSS 6.5
CVE-2020-28907
CRITICAL
Nagios Fusion < 4.1.8 - Improper Certificate Validation in Update Package Download
CVSS 9.8
CVE-2020-36127
MEDIUM
PAXSTORE < 7.0.8_20200511171508 - Information Disclosure via PUK Signature Certificate Replacement
CVSS 6.5
CVE-2020-7924
MEDIUM
MongoDB Database Tools <100.2.0, Mongomirror <0.6.0 - Improper Certificate Validation
CVSS 4.2
CVE-2020-15260
MEDIUM
PJSIP < 2.10 - Improper Certificate Validation
CVSS 6.8
CVE-2020-35662
HIGH
SaltStack Salt < 2015.8.10 - Improper Certificate Validation
CVSS 7.4
CVE-2020-28972
MEDIUM
SaltStack Salt < 3002.5 - Improper Certificate Validation in VMware Authentication
CVSS 5.9
CVE-2020-24393
MEDIUM
TweetStream 2.6.1 - Man-in-the-Middle
CVSS 5.9
CVE-2020-24392
MEDIUM
voloko twitter-stream <0.1.10 - SSRF
CVSS 5.9
CVE-2020-29457
MEDIUM
OPC UA .NET Standard Stack <1.4.363.107 - Privilege Escalation
CVSS 4.4
CVE-2020-4791
MEDIUM
IBM Security Identity Governance and Intelligence 5.2.6 - Improper Certificate Validation
CVSS 5.3
CVE-2020-5812
MEDIUM
Nessus AMI <8.12.0 - Info Disclosure
CVSS 5.9
CVE-2020-35733
HIGH
Erlang/OTP < 23.2.2 - Improper Certificate Validation
CVSS 7.5
CVE-2020-24025
MEDIUM
node-sass <4.14.1 - Info Disclosure
CVSS 5.3
CVE-2020-25680
MEDIUM
JBCS httpd 2.4.37 SP3 - Improper Certificate Validation
CVSS 5.4
CVE-2020-8289
HIGH
Backblaze <7.0.1.433-7.0.1.434 - RCE
CVSS 7.8
CVE-2020-5684
MEDIUM
iSM client <V12.1 - Man-in-the-Middle
CVSS 4.8
CVE-2020-29663
CRITICAL
Icinga 2 <2.11.7, <2.12.2 - Info Disclosure
CVSS 9.1
CVE-2020-8286
HIGH
libcurl 7.41.0-7.73.0 - Improper Certificate Validation via OCSP Response
CVSS 7.5
CVE-2020-29440
MEDIUM
Tesla Model X Firmware < 2020-11-23 - Improper Certificate Validation in Key Fob Pairing
CVSS 4.6
CVE-2020-28942
MEDIUM
PrimeKey EJBCA < 7.4.3 - Certificate Validation Bypass via EST Enrollment
CVSS 4.3
CVE-2020-8279
HIGH
Nextcloud Social < 0.4.0 - Info Disclosure
CVSS 7.4
Details
Vulnerabilities
1,400