Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS cert
Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was prese
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust
A vulnerability was found in Hualai Xiaofang iSC5 3.2.2_112 and classified as problematic. Affected by this issue is som
A vulnerability was found in EZVIZ CS-C6-21WFR-8 5.2.7 Build 170628. It has been classified as problematic. This affects
An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application
Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate v
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged at
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secr
Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, cer
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability b
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two di
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS h
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid cr
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to i
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensit
Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send email
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are acc
If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a m
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the sam
Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS base
Improper Certificate Validation vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe comp
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 throu
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a ce
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remo
In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unaut
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS c
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override othe
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by def
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability du
Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a ne
Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the netwo
MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code
MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execut
MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code
MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code executio
MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly v
A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is select
Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started