Skip to content
Noroxi

CWE-296 · 14 records

Improper Following of a Certificate's Chain of Trust

CVEs in this class

14 records

  • Icinga 2 certificate renewal might incorrectly renew an invalid certificate

    CriticalCVSS 9.3No exploitEPSS 0%

    icinga · icingaMay 27, 2025

  • s2s-proxy accepts untrusted client certificates

    CriticalCVSS 9.3No exploitEPSS 0%

    temporal technologies, inc. · s2s-proxySep 23, 2026

  • Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication

    HighCVSS 8.3No exploitEPSS 0%

    juniper · junosApr 9, 2026

  • Slate Digital Connect macOS XPC certificate validation privilege escalation

    HighCVSS 8.4No exploitEPSS 0%

    slate digital llc · slate digital connectJun 10, 2026

  • Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C

    HighCVSS 8.1No exploitEPSS 0%

    gallagher · command centre mobile connectNov 18, 2021

  • CVE-2025-1146
    32Monitor

    CrowdStrike Falcon Sensor for Linux TLS Issue

    HighCVSS 8.1No exploitEPSS 0%

    crowdstrike · falcon sensor for linuxFeb 12, 2025

  • CVE-2019-3762
    30Monitor

    Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability.

    HighCVSS 7.5No exploitEPSS 1%

    dell · emc data protection centralMar 18, 2020

  • CVE-2021-1566
    29Monitor

    Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability

    HighCVSS 7.4No exploitEPSS 1%

    cisco · email security applianceJun 16, 2021

  • Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interface

    HighCVSS 7.2No exploitEPSS 1%

    arubanetworks · arubaosMay 12, 2026

  • Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce

    MediumCVSS 6.8No exploitEPSS 0%

    gallagher · command centre mobile clientNov 18, 2021

  • Multiple SEIKO EPSON printers and scanners contain revoked root certificates.

    MediumCVSS 6.3No exploitEPSS 0%

    seiko epson corporation · multiple seiko epson printers and scannersAug 20, 2026

  • Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format.

    MediumCVSS 5.3No exploitEPSS 10%

    nodejs · node.jsFeb 24, 2022

  • Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticate

    MediumCVSS 4.8No exploitEPSS 0%

    ivanti · endpoint managerApr 8, 2025

  • IBM OpenPages data manipulation

    MediumCVSS 4.3No exploitEPSS 0%

    ibm · openpages with watsonFeb 20, 2025

All vulnerability classes