In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not valida
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositor
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero C
Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common N
FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the Fre
Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26
Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the confi
The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Crede
Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to b
Windows Certificate Spoofing Vulnerability
The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.
An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alt
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the
Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM
Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to byp
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should ha
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when conn
IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM
An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a tru
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificat
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/T
Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer sec
Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when s
Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc impleme
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN t
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocol
The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using t
A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker t
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, T
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate wou
A vulnerability has been identified in Industrial Edge Management (All versions < V1.5.1). The affected software does no
In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could l
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify
In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local es
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations t
`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to th
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate expli
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have le
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started