Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intende
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are n
Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL pr
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certa
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verificatio
Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code
The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-midd
The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-t
The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificat
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, re
Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verific
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf
In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle atta
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-m
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypas
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended acce
In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client o
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certif
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Serve
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-mid
An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the E
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation.
wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in t
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softw
HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the syste
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Stud
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the s
IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients base
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were le
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kube
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someo
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it pos
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potenti
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started