A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0
Sensitive information disclosure and manipulation due to improper certification validation. The following products are a
Sensitive information disclosure and manipulation due to improper certification validation. The following products are a
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information d
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used
A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to conne
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certifi
Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44.
Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions be
An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow a
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostna
Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and
Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host
An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior
A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the se
Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation v
In JetBrains Ktor before 2.3.5 server certificates were not verified
Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A loc
A user with a compromised configuration can start an unsigned binary as a service.
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when
Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be ena
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certific
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certif
It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.
It was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net
It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Stora
A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclos
The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing appl
BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.
Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server
Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.
GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-th
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patt
Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 ar
Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to
MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to
OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-mid
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authen
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whe
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the netw
An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to exte
Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started