If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server th
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensiti
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could al
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communic
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communic
In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket conn
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100,
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an
In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly valid
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provi
An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client con
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreS
Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in
TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, t
Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, eve
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or
A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direc
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the exis
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It u
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly.
The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a cert
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL
A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certific
In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds,
'Hulu / フールー' App for iOS versions prior to 3.0.81 improperly verifies server certificates, which may allow an attacker
Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST d
WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of
OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.
Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless serv
Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILT
Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1.x 19.3.x, 19.3.0.x, 19.4.x, 19.4.0.x, 1
'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may al
Dell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unaut
Cosign provides container signing, verification, and storage in an OCI registry for the sigstore project. Prior to versi
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms coul
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptogra
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Exec
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate informa
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUn
WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI ve
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the l
Microsoft Defender for IoT Remote Code Execution Vulnerability
Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform.
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started