CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,400 vulnerabilities with CWE-295
CVE-2020-24613 MEDIUM
wolfSSL <4.5.0 - Privilege Escalation
CVSS 6.8
CVE-2020-17366 HIGH
NLnet Labs Routinator <0.7.1 - Auth Bypass/DoS
CVSS 7.4
CVE-2020-15134 HIGH
Faye < 1.4.0 - Missing TLS Certificate Validation
CVSS 8.0
CVE-2020-15133 HIGH
Faye-websocket <0.11.0 - SSL/TLS Info Disclosure
CVSS 8.0
CVE-2020-16164 HIGH
RIPE NCC RPKI Validator 3.x < 3.1-2020.07.06.14.28 - Improper Certificate Validation
CVSS 7.4
CVE-2020-16163 CRITICAL
RIPE NCC RPKI Validator 3.x < 3.1-2020.07.06.14.28 - Improper Certificate Validation
CVSS 9.1
CVE-2020-16162 HIGH
RIPE NCC RPKI Validator 3.x < 3.1-2020.07.06.14.28 - Improper Certificate Validation
CVSS 7.5
CVE-2020-10925 HIGH
NETGEAR R6700 V1.0.4.84_10.0.58 - Info Disclosure
CVSS 8.8
CVE-2020-6529 MEDIUM
Google Chrome < 84.0.4147.89 - Cross-Origin Data Leak via WebRTC
CVSS 4.3
CVE-2020-15813 HIGH
Graylog < 3.3.3 - Improper Certificate Validation for LDAP Servers
CVSS 8.1
CVE-2020-14039 MEDIUM
GO < 1.13.13 - Improper Certificate Validation
CVSS 5.3
CVE-2020-15720 MEDIUM
Dogtagpki < 10.8.3 - Improper Certificate Validation
CVSS 6.8
CVE-2020-15719 MEDIUM
OpenLDAP < 2.4.46-10.el8 - Improper Certificate Validation
CVSS 4.2
CVE-2020-15526 MEDIUM
Redgate SQL Monitor 7.1.4-10.1.6 - Improper Certificate Validation in Alert Notifications and VMware Monitoring
CVSS 5.9
CVE-2020-12421 MEDIUM
Firefox ESR < 68.10 - Info Disclosure
CVSS 6.5
CVE-2020-5909 MEDIUM
NGINX Controller <3.5.0, <2.9.0, <1.0.1 - Info Disclosure
CVSS 5.4
CVE-2020-15047 MEDIUM
Trojita < 0.8 - Improper Certificate Validation in MSA/SMTP.cpp
CVSS 5.9
CVE-2020-5367 HIGH
Dell EMC Unisphere for PowerMax < 9.1.0.17 - Unauthenticated Man-in-the-Middle via Improper Certificate Validation
CVSS 7.4
CVE-2020-14981 MEDIUM
ThreatTrack VIPRE Password Vault <1.100.1090 - Info Disclosure
CVSS 5.9
CVE-2020-14980 MEDIUM
Sophos Secure Email <3.9.4 - Info Disclosure
CVSS 5.9
CVE-2020-3342 HIGH
Cisco Webex Meetings Desktop App for Mac - RCE
CVSS 8.8
CVE-2020-4320 MEDIUM
IBM MQ 8.0.0.0-8.0.0.14, 9.0.0.0-9.0.0.9, 9.1.0-9.1.4 - Improper Certificate Validation in AMQP Channels
CVSS 6.5
CVE-2020-2033 MEDIUM
GlobalProtect 5.0.0-5.0.9 - Authentication Bypass via ARP Spoofing
CVSS 5.3
CVE-2020-0119 MEDIUM
Android 10 - Man-in-the-Middle Attack via Improper Certificate Validation in WifiConfigManager
CVSS 5.3
CVE-2020-9040 HIGH
Couchbase Server Java SDK 1.7.1-2.7.1 - Improper Certificate Validation in Netty Component
CVSS 7.5
Details
Vulnerabilities 1,400