Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2021-08-19 CVE-2021-37698 Improper Certificate Validation vulnerability in multiple products
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting.
network
low complexity
icinga debian CWE-295
7.5
2021-08-18 CVE-2021-32728 Improper Certificate Validation vulnerability in multiple products
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer.
network
low complexity
nextcloud debian CWE-295
6.5
2021-08-16 CVE-2021-22939 Improper Certificate Validation vulnerability in multiple products
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
network
low complexity
nodejs oracle netapp siemens debian CWE-295
5.3
2021-08-13 CVE-2021-32069 Improper Certificate Validation vulnerability in Mitel Micollab
The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to improper TLS negotiation.
network
high complexity
mitel CWE-295
4.8
2021-08-13 CVE-2021-31399 Improper Certificate Validation vulnerability in 2N Access Unit 2.0 Firmware 2.31.0.40.5
On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack.
network
high complexity
2n CWE-295
5.9
2021-08-05 CVE-2021-22926 Improper Certificate Validation vulnerability in multiple products
libcurl-using applications can ask for a specific client certificate to be used in a transfer.
network
low complexity
haxx netapp oracle siemens splunk CWE-295
7.5
2021-08-05 CVE-2021-32581 Improper Certificate Validation vulnerability in Acronis products
Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 27009 did not implement SSL certificate validation.
network
low complexity
acronis CWE-295
8.1
2021-07-30 CVE-2021-35193 Improper Certificate Validation vulnerability in Pattersondental Eaglesoft
Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers' installations (that have the same software version).
network
low complexity
pattersondental CWE-295
7.5
2021-07-26 CVE-2020-12681 Improper Certificate Validation vulnerability in 3Xlogic Infinias Eidc32 Firmware 2.213/3.4.125
Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/control the channel by which door lock policies are applied.
network
low complexity
3xlogic CWE-295
7.5
2021-07-19 CVE-2020-36425 Improper Certificate Validation vulnerability in multiple products
An issue was discovered in Arm Mbed TLS before 2.24.0.
network
low complexity
arm debian CWE-295
5.3