The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM
An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-auth
Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue
In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are n
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates d
Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service
Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contai
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1
An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of response
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate
IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could a
OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used f
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterpris
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-sid
Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R00
Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as v
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validat
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful e
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of retu
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate valid
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code
The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involv
A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation duri
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequen
A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vu
VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle att
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bind
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using
brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) cont
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote una
Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbi
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W
An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and p
An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration o
An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade thir
An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously craf
An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade thi
An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code sign
An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing che
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_R
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and
Huawei AR3200 V200R008C20, V200R008C30, TE40 V600R006C00, TE50 V600R006C00, TE60 V600R006C00 have a denial of service vu
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which
TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature.
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started