Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept t
Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to interce
Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept tr
Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercep
WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor en
Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of inf
Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerabilit
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0,
KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed i
An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the S
Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-653
In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potent
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to
CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with acces
Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not align
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure s
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obta
JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL versio
A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an u
A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_t
Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io
GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be prob
Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker
An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could all
BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handlin
"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insuffici
When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the drive
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with
A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VA
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect t
An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges
PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment a
MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli
Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0
go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness
Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Au
Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verificati
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthe
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the
An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not
The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which ma
NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerabili
An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications al
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started