CWE-296 · 14 records
Improper Following of a Certificate's Chain of Trust
CVEs in this class
14 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2025-48057No exploit | Icinga 2 certificate renewal might incorrectly renew an invalid certificateicinga · icinga · CWE-296 | Critical9.3 | — | 0.4% | May 27, 2025 |
37Monitor | CVE-2026-96770No exploit | s2s-proxy accepts untrusted client certificatestemporal technologies, inc. · s2s-proxy · CWE-296 | Critical9.3 | — | 0.3% | Sep 23, 2026 |
33Monitor | CVE-2026-33779No exploit | Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communicationjuniper · junos · CWE-296 | High8.3 | — | 0.2% | Apr 9, 2026 |
33Monitor | CVE-2026-24066No exploit | Slate Digital Connect macOS XPC certificate validation privilege escalationslate digital llc · slate digital connect · CWE-296 | High8.4 | — | 0.1% | Jun 10, 2026 |
32Monitor | CVE-2021-23162No exploit | Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Cgallagher · command centre mobile connect · CWE-296 | High8.1 | — | 0.4% | Nov 18, 2021 |
32Monitor | CVE-2025-1146No exploit | CrowdStrike Falcon Sensor for Linux TLS Issuecrowdstrike · falcon sensor for linux · CWE-296 | High8.1 | — | 0.3% | Feb 12, 2025 |
30Monitor | CVE-2019-3762No exploit | Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability.dell · emc data protection central · CWE-296 | High7.5 | — | 0.6% | Mar 18, 2020 |
29Monitor | CVE-2021-1566No exploit | Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerabilitycisco · email security appliance · CWE-296 | High7.4 | — | 0.7% | Jun 16, 2021 |
28Monitor | CVE-2026-44852No exploit | Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interfacearubanetworks · arubaos · CWE-296 | High7.2 | — | 0.6% | May 12, 2026 |
27Monitor | CVE-2021-23155No exploit | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Cegallagher · command centre mobile client · CWE-296 | Medium6.8 | — | 0.5% | Nov 18, 2021 |
25Monitor | CVE-2026-73542No exploit | Multiple SEIKO EPSON printers and scanners contain revoked root certificates.seiko epson corporation · multiple seiko epson printers and scanners · CWE-296 | Medium6.3 | — | 0.2% | Aug 20, 2026 |
24Monitor | CVE-2021-44532No exploit | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format.nodejs · node.js · CWE-296 | Medium5.3 | — | 10.4% | Feb 24, 2022 |
19Monitor | CVE-2025-22459No exploit | Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticateivanti · endpoint manager · CWE-296 | Medium4.8 | — | 0.3% | Apr 8, 2025 |
17Monitor | CVE-2024-43196No exploit | IBM OpenPages data manipulationibm · openpages with watson · CWE-296 | Medium4.3 | — | 0.2% | Feb 20, 2025 |
- CVE-2025-4805737Monitor
Icinga 2 certificate renewal might incorrectly renew an invalid certificate
CriticalCVSS 9.3No exploitEPSS 0%icinga · icingaMay 27, 2025
- CVE-2026-9677037Monitor
s2s-proxy accepts untrusted client certificates
CriticalCVSS 9.3No exploitEPSS 0%temporal technologies, inc. · s2s-proxySep 23, 2026
- CVE-2026-3377933Monitor
Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
HighCVSS 8.3No exploitEPSS 0%juniper · junosApr 9, 2026
- CVE-2026-2406633Monitor
Slate Digital Connect macOS XPC certificate validation privilege escalation
HighCVSS 8.4No exploitEPSS 0%slate digital llc · slate digital connectJun 10, 2026
- CVE-2021-2316232Monitor
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C
HighCVSS 8.1No exploitEPSS 0%gallagher · command centre mobile connectNov 18, 2021
- CVE-2025-114632Monitor
CrowdStrike Falcon Sensor for Linux TLS Issue
HighCVSS 8.1No exploitEPSS 0%crowdstrike · falcon sensor for linuxFeb 12, 2025
- CVE-2019-376230Monitor
Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability.
HighCVSS 7.5No exploitEPSS 1%dell · emc data protection centralMar 18, 2020
- CVE-2021-156629Monitor
Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability
HighCVSS 7.4No exploitEPSS 1%cisco · email security applianceJun 16, 2021
- CVE-2026-4485228Monitor
Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interface
HighCVSS 7.2No exploitEPSS 1%arubanetworks · arubaosMay 12, 2026
- CVE-2021-2315527Monitor
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce
MediumCVSS 6.8No exploitEPSS 0%gallagher · command centre mobile clientNov 18, 2021
- CVE-2026-7354225Monitor
Multiple SEIKO EPSON printers and scanners contain revoked root certificates.
MediumCVSS 6.3No exploitEPSS 0%seiko epson corporation · multiple seiko epson printers and scannersAug 20, 2026
- CVE-2021-4453224Monitor
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format.
MediumCVSS 5.3No exploitEPSS 10%nodejs · node.jsFeb 24, 2022
- CVE-2025-2245919Monitor
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticate
MediumCVSS 4.8No exploitEPSS 0%ivanti · endpoint managerApr 8, 2025
- CVE-2024-4319617Monitor
IBM OpenPages data manipulation
MediumCVSS 4.3No exploitEPSS 0%ibm · openpages with watsonFeb 20, 2025