An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes
Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers
Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof
This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When thi
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM
A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid t
2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verif
Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate valid
BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the ma
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connect
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connect
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior t
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi
Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects M
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2
Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazo
An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remot
Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-4
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host na
syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain
Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that as
Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router)
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not
A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zon
pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate ver
Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be p
Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communica
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attack
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify
SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app expli
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-
Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to cond
F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Sof
OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSe
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server c
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certi
A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts se
Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated me
IBM OpenPages with Watson 8.3 and 9.0 could allow a remote attacker to spoof mail server identity when using SSL/TLS
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started