A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phi
kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authen
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped fo
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerabil
dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present
An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoo
Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configurati
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.
MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote r
Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certifica
For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will au
Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided b
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows
lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also a
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This i
eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0,
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane co
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attac
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the con
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.
stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server t
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildca
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLA
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a
An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the manageme
A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is conf
Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows atta
Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adv
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potent
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was process
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to
Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vi
An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability c
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerabi
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerabi
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerabi
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerabi
An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started