Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2020-05-12 CVE-2020-8156 Improper Certificate Validation vulnerability in multiple products
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
network
high complexity
nextcloud fedoraproject CWE-295
7.0
2020-05-11 CVE-2020-10059 Improper Certificate Validation vulnerability in Zephyrproject Zephyr 2.1.0/2.2.0
The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack.
network
high complexity
zephyrproject CWE-295
4.8
2020-05-09 CVE-2020-12637 Improper Certificate Validation vulnerability in Zulipchat Zulip Desktop
Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.
network
low complexity
zulipchat CWE-295
critical
9.8
2020-05-07 CVE-2020-11050 Improper Certificate Validation vulnerability in Java-Websocket Project Java-Websocket
In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation.
network
high complexity
java-websocket-project CWE-295
8.1
2020-05-06 CVE-2020-2187 Improper Certificate Validation vulnerability in Jenkins Amazon EC2
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.
network
high complexity
jenkins CWE-295
5.6
2020-05-05 CVE-2020-12144 Improper Certificate Validation vulnerability in Silver-Peak products
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated.
network
low complexity
silver-peak CWE-295
4.9
2020-05-05 CVE-2020-12143 Improper Certificate Validation vulnerability in Silver-Peak products
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
network
low complexity
silver-peak CWE-295
4.9
2020-04-29 CVE-2019-19101 Improper Certificate Validation vulnerability in Br-Automation Automation Studio
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade server.
network
high complexity
br-automation CWE-295
5.9
2020-04-27 CVE-2020-1952 Improper Certificate Validation vulnerability in Apache Iotdb
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.
network
low complexity
apache CWE-295
critical
9.8
2020-04-27 CVE-2020-9488 Improper Certificate Validation vulnerability in multiple products
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender.
network
high complexity
apache oracle debian qos CWE-295
3.7