Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allow
HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6
packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by t
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavio
In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the Fet
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4,
The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communicat
Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent
Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive infor
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the
An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certif
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due t
A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4,
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired cer
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enab
libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-mid
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination
Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/co
Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across di
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CU
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parame
The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed b
IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate valida
The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO Active
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alt
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alt
An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, S
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of
core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not alway
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain.
The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validati
A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Emai
A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could a
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authenticatio
A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (Al
The SNKRDUNK Market Place App for iOS versions prior to 2.2.0 does not verify server certificate properly, which allows
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS
A vulnerability has been identified in SINUMERIK Edge (All versions < V3.2). The affected software does not properly val
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started