The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenti
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certifi
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.
Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for i
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the serv
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvi
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same ce
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, in
Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client co
Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (t
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValid
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Security" comp
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). W
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certifica
EMC RSA BSAFE Cert-C before 2.9.0.5 contains a potential improper certificate processing vulnerability.
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
An issue was discovered in heinekingmedia StashCat before 1.5.18 for Android. No certificate pinning is implemented; the
A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, aut
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mech
Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS tr
On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS befor
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NE
Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly va
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manage
Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to exec
niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-t
Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus
In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the serv
Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Auth
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by l
Google Chrome caches TLS sessions before certificate validation occurs.
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and Po
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which m
An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a c
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7
DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started