Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket cla
The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from server
Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.
In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the v
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not pe
Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to
In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks ca
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server cert
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS ce
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the S
In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::Ver
HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnera
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostn
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connect
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate va
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate va
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while se
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly ve
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle att
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can di
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU re
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthen
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate
IBM QRadar 7.3.0 to 7.3.3 Patch 2 does not validate, or incorrectly validates, a certificate which could allow an attack
The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firm
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP serve
Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured S
iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not veri
Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob w
Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validati
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged networ
An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that
IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate vali
An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protoc
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asser
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate val
A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MI
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connectio
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started