CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,400 vulnerabilities with CWE-295
CVE-2019-10382 MEDIUM
Jenkins VMware Lab Manager Slaves Plugin <= 0.2.8 - Improper Certificate Validation
CVSS 6.5
CVE-2019-10381 HIGH
Jenkins Codefresh Integration Plugin < 1.8 - SSL/TLS and Hostname Verification Disabled
CVSS 7.5
CVE-2019-3890 HIGH
evolution-ews < 3.31.3 - Improper Certificate Validation
CVSS 8.1
CVE-2019-14334 MEDIUM
D-Link 6600-AP - Privilege Escalation
CVSS 5.5
CVE-2019-7615 HIGH
Elastic APM agent for Ruby <2.9.0 - Info Disclosure
CVSS 7.4
CVE-2019-1552 LOW
OpenSSL 1.0.2-1.0.2s - Improper Certificate Validation via OPENSSLDIR Configuration
CVSS 3.3
CVE-2019-11727 MEDIUM
Firefox < 68.0 - Improper Certificate Validation via PKCS#1 v1.5 Signatures in TLS 1.3
CVSS 5.3
CVE-2019-1010206 MEDIUM
OSS Http Request (Apache Cordova Plugin) 6 - SSL Spoofing
CVSS 5.9
CVE-2019-1940 MEDIUM
Cisco Industrial Network Director < 1.7 - Unauthenticated Sensitive Data Exposure via Invalid X.509 Certificate
CVSS 5.9
CVE-2019-1010275 CRITICAL
helm <2.7.2 - Improper Certificate Validation
CVSS 9.8
CVE-2019-1006 HIGH
.NET Framework - Authentication Bypass via SAML Token Arbitrary Symmetric Key Signing
CVSS 7.5
CVE-2019-11242 HIGH
Cohesity DataPlatform 5.x-6.x < 6.1.1c - Man-in-the-Middle via vCenter TLS Certificate Validation Bypass
CVSS 8.1
CVE-2019-9148 MEDIUM
Mailvelope < 3.3.0 - Improper Certificate Validation
CVSS 4.3
CVE-2019-5961 HIGH
Tootdon for Mastodon < 3.4.1 - Improper Certificate Validation
CVSS 7.4
CVE-2019-1886 HIGH
Cisco AsyncOS 10.5-10.5.5-005 - Denial of Service via Malformed SSL Certificate
CVSS 8.6
CVE-2019-13050 HIGH
GnuPG < 2.2.16 - Denial of Service via SKS Keyserver Certificate Spamming
CVSS 7.5
CVE-2019-4150 LOW
IBM Security Access Manager 9.0.1-9.0.6 - Improper Certificate Validation
CVSS 3.7
CVE-2019-12855 HIGH
Twisted < 19.2.1 - Improper Certificate Validation in XMPP TLS Connections
CVSS 7.4
CVE-2019-3875 MEDIUM
Keycloak < 6.0.2 - Improper Certificate Validation in X.509 Authenticator
CVSS 6.5
CVE-2019-10334 MEDIUM
Jenkins ElectricFlow < 1.1.5 - SSL/TLS and Hostname Verification Disabled via MultipartUtility.java
CVSS 6.5
CVE-2019-12496 HIGH
Hybrid Group Gobot < 1.13.0 - Improper Certificate Validation in MQTT Subsystem
CVSS 7.5
CVE-2019-4264 MEDIUM
IBM QRadar SIEM <7.2.8 - Info Disclosure
CVSS 5.9
CVE-2019-12098 HIGH
Heimdal <7.6.0 - Privilege Escalation
CVSS 7.4
CVE-2019-11550 MEDIUM
Citrix SD-WAN 10.2.x < 10.2.1 and NetScaler SD-WAN 10.0.x < 10.0.7 - Improper Certificate Validation
CVSS 5.9
CVE-2019-1859 HIGH
Cisco Small Business Switches - Auth Bypass
CVSS 7.2
Details
Vulnerabilities 1,400