Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2019-07-17 CVE-2019-1940 Improper Certificate Validation vulnerability in Cisco Industrial Network Director
A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid X.509 certificate.
network
cisco CWE-295
4.3
2019-07-17 CVE-2019-1010275 Improper Certificate Validation vulnerability in Helm
helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation.
network
low complexity
helm CWE-295
7.5
2019-07-15 CVE-2019-1006 Improper Certificate Validation vulnerability in Microsoft products
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
network
low complexity
microsoft CWE-295
5.0
2019-07-12 CVE-2019-11242 Improper Certificate Validation vulnerability in Cohesity Dataplatform
A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c.
network
cohesity CWE-295
4.3
2019-07-09 CVE-2019-9148 Improper Certificate Validation vulnerability in Mailvelope
Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain users without a valid self-certification.
4.3
2019-07-05 CVE-2019-5961 Improper Certificate Validation vulnerability in Mastodon-Tootdon Tootdon FOR Mastodon
The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
5.8
2019-07-04 CVE-2019-1886 Improper Certificate Validation vulnerability in Cisco Asyncos and web Security Appliance
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-295
5.0
2019-06-29 CVE-2019-13050 Improper Certificate Validation vulnerability in multiple products
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network.
7.5
2019-06-25 CVE-2019-4150 Improper Certificate Validation vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
network
high complexity
ibm CWE-295
3.7
2019-06-24 CVE-2017-17945 Improper Certificate Validation vulnerability in Asus Hivivo and Vivobaby
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
network
low complexity
asus CWE-295
6.4