Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2020-12-15 CVE-2020-29663 Improper Certificate Validation vulnerability in Icinga
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL.
network
low complexity
icinga CWE-295
critical
9.1
2020-12-14 CVE-2020-8286 Improper Certificate Validation vulnerability in multiple products
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
7.5
2020-12-02 CVE-2012-0955 Improper Certificate Validation vulnerability in Canonical Software-Properties 0.81.13.1/0.81.13.3
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py.
network
high complexity
canonical CWE-295
7.4
2020-11-30 CVE-2020-29440 Improper Certificate Validation vulnerability in Tesla Model X Firmware
Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM).
low complexity
tesla CWE-295
4.6
2020-11-19 CVE-2020-28942 Improper Certificate Validation vulnerability in Primekey Ejbca
An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol.
network
low complexity
primekey CWE-295
4.3
2020-11-19 CVE-2020-8279 Improper Certificate Validation vulnerability in Nextcloud Social
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.
network
high complexity
nextcloud CWE-295
7.4
2020-11-18 CVE-2020-28362 Improper Certificate Validation vulnerability in multiple products
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
network
low complexity
golang fedoraproject netapp CWE-295
7.5
2020-11-06 CVE-2020-27589 Improper Certificate Validation vulnerability in Synopsys Hub-Rest-Api-Python
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
network
low complexity
synopsys CWE-295
7.5
2020-10-29 CVE-2020-27649 Improper Certificate Validation vulnerability in Synology Router Manager
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
synology CWE-295
critical
9.0
2020-10-29 CVE-2020-27648 Improper Certificate Validation vulnerability in Synology Diskstation Manager and Skynas Firmware
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
synology CWE-295
critical
9.0