The product does not validate, or incorrectly validates, a certificate.
1,400 vulnerabilities with CWE-295
CVE-2018-5408
HIGH
PrinterLogic Print Management <18.3.1.96 - Man-in-the-Middle
CVSS 7.4
CVE-2018-20200
MEDIUM
OkHttp 3.0.0-3.12.0 - Certificate Pinning Bypass via SSLContext Manipulation
CVSS 5.9
CVE-2018-4436
HIGH
iPhone OS < 12.1.1 - Improper Certificate Validation in Configuration Profiles
CVSS 7.5
CVE-2018-5926
CRITICAL
HP Remote Graphics Software <7.5.0 - Info Disclosure
CVSS 9.1
CVE-2018-6517
HIGH
chloride < 0.3.0 - Improper Certificate Validation via net-ssh Host Fingerprint Handling
CVSS 7.5
CVE-2018-11747
CRITICAL
Puppet Discovery < 1.4.0 - Improper Certificate Validation
CVSS 9.8
CVE-2018-12205
MEDIUM
Intel Platform Sample/Silicon Reference Firmware - Improper Certificate Validation
CVSS 6.8
CVE-2018-20245
HIGH
Apache Airflow <1.10.1 - Info Disclosure
CVSS 7.5
CVE-2018-15784
HIGH
Dell Networking OS10 < 10.4.3.0 - Improper Certificate Validation in Phone Home Feature
CVSS 7.4
CVE-2018-16187
MEDIUM
Ricoh D2200 Firmware < 2.2 - Improper Certificate Validation
CVSS 5.9
CVE-2018-16179
MEDIUM
Mizuho Direct App < 3.13.0 - Improper Certificate Validation
CVSS 5.9
CVE-2018-1320
HIGH
Apache Thrift 0.5.0-0.11.0 - Improper Certificate Validation in SASL Negotiation
CVSS 7.5
CVE-2018-4015
HIGH
Webroot BrightCloud SDK - Improper Certificate Validation in HTTP Client
CVSS 8.1
CVE-2018-16875
MEDIUM
Go <1.10.6/1.11.x - DoS
CVSS 5.9
CVE-2018-19982
MEDIUM
KT MC01507L Z-Wave S0 - Info Disclosure
CVSS 5.3
CVE-2018-0691
MEDIUM
KDDI, NTT DOCOMO, and Softbank +Message Apps - Improper Certificate Validation
CVSS 5.9
CVE-2018-17187
HIGH
Apache Qpid Proton-J 0.3-0.29.0 - Improper Certificate Validation in TLS Transport Wrapper
CVSS 7.4
CVE-2018-17612
HIGH
Sennheiser HeadSetup <7.3.4903 - SSL/TLS Spoofing
CVSS 7.5
CVE-2018-15326
HIGH
BIG-IP APM Improper Certificate Validation in CRLDP Auth Access Policy Agent
CVSS 7.5
CVE-2018-18568
MEDIUM
Polycom Unified Communications Software < 5.8.0.12848 - Improper Certificate Validation
CVSS 5.9
CVE-2018-18567
MEDIUM
AudioCodes 440HD and 450HD Firmware < 3.1.2.89 - Improper Certificate Validation
CVSS 5.9
CVE-2018-15387
CRITICAL
Cisco SD-WAN Solution - Auth Bypass
CVSS 9.8
CVE-2018-0434
HIGH
Cisco SD-WAN < 18.3.0 - Unauthenticated Sensitive Data Exposure via ZTP
CVSS 7.4
CVE-2018-12087
MEDIUM
OPC Foundation UA Client - Info Disclosure
CVSS 5.3
CVE-2018-1509
LOW
IBM Security Guardium EcoSystem 10.5 - Improper Certificate Validation
CVSS 3.7
Details
Vulnerabilities
1,400