An issue existed in the handling of S-MIME certificates. This issue was addressed with improved validation of S-MIME cer
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer ov
helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could co
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name
European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a
European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain Exp
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 prot
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used in
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The
On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or ser
Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attac
A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process versio
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, re
Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins ma
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-
A vulnerability in the Transport Layer Security (TLS) certificate validation functionality of Cisco Nexus 9000 Series Ap
Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of appl
A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse t
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability
Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contai
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote at
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and con
An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to improperly implemented TLS certif
Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting add
A certificate validation issue existed in configuration profiles. This was addressed with additional checks. This issue
The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is differ
An issue was discovered in Hybrid Group Gobot before 1.13.0. The mqtt subsystem skips verification of root CA certificat
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes i
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation
Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDC
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https con
Python Twisted 14.0 trustRoot is not respected in HTTP client
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a clie
duplicity 0.6.24 has improper verification of SSL certificates
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabl
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started