The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the mid
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con
A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed c
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does
SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affect
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i
This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of Charg
Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mod
IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication pat
IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate val
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use f
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an I
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below m
A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol a
Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.
Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged atta
Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying coun
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disab
The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the insta
An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certifi
An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Prote
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data o
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitiv
An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious act
Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vuln
HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9
A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, co
Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate T
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0,
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the
Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in
When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL c
MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it
Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certifi
In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote inform
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential
An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation
A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Cert
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow inform
A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under ce
A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could all
An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a r
libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is n
Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started