CWE-295 · 1 502 записей
Некорректная проверка сертификата
Почему это происходит?
Ошибка проверки сертификата незаметно подавляется вместо разрыва соединения. Часто это код, добавленный для тестовой среды и попавший в продуктивную.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
override fun checkServerTrusted(chain: Array<X509Certificate>, type: String) { // Оставлено пустым для тестовой среды}Исправленный код
val client = OkHttpClient.Builder() .certificatePinner( CertificatePinner.Builder() .add("api.sirius.example", "sha256/…") .build() ).build()Как предотвратить
- 01Не изменяйте стандартную цепочку доверия платформы.
- 02В критичных приложениях используйте закрепление сертификатов (pinning).
- 03Не допускайте попадания тестовых конфигураций в продуктивную сборку.
CVE этого класса
1 504 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2022-26923Готовый эксплойт | Active Directory Domain Services Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-295 | Высокая8,8 | KEV | 83,5 % | 10 мая 2022 г. |
89Срочно | CVE-2020-0601Готовый эксплойт | A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacmicrosoft · windows 10 1507 · CWE-295 | Высокая8,1 | KEV | 89,4 % | 14 янв. 2020 г. |
71На этой неделе | CVE-2026-85102Готовый эксплойт | Improper Certificate Validation in Quantum Security Gatewaycheckpoint · gaia embedded · CWE-295 | Критическая9,8 | KEV | 7,5 % | 9 сент. 2026 г. |
65На этой неделе | CVE-2009-3555Proof of concept | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Критическая9,8 | — | 87,3 % | 9 нояб. 2009 г. |
61На этой неделе | CVE-2023-20963Готовый эксплойт | In WorkSource, there is a possible parcel mismatch.google · android · CWE-295 | Высокая7,8 | KEV | 1,5 % | 24 мар. 2023 г. |
56В плане | CVE-2023-41991Готовый эксплойт | A certificate validation issue was addressed.apple · ipados · CWE-295 | Средняя5,5 | KEV | 13,4 % | 21 сент. 2023 г. |
42В плане | CVE-2022-42979Эксплойта нет | Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ovrydesharing · ryde · CWE-295 | Высокая8,8 | — | 24,3 % | 6 янв. 2023 г. |
42В плане | CVE-2017-2800Proof of concept | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certifwolfssl · wolfssl · CWE-295 | Критическая9,8 | — | 8,5 % | 24 мая 2017 г. |
41В плане | CVE-2018-12829Эксплойта нет | Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability.adobe · creative cloud · CWE-295 | Критическая9,8 | — | 5,1 % | 29 авг. 2018 г. |
40В плане | CVE-2018-4991Эксплойта нет | Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability.adobe · creative cloud · CWE-295 | Критическая9,8 | — | 4,0 % | 19 мая 2018 г. |
40В плане | CVE-2015-2320Эксплойта нет | The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.mono-project · mono · CWE-295 | Критическая9,8 | — | 3,5 % | 8 янв. 2018 г. |
40В плане | CVE-2020-28907Эксплойта нет | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via venagios · fusion · CWE-295 | Критическая9,8 | — | 3,4 % | 24 мая 2021 г. |
40В плане | CVE-2018-21029Эксплойта нет | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.systemd project · systemd · CWE-295 | Критическая9,8 | — | 3,1 % | 30 окт. 2019 г. |
40В плане | CVE-2021-33907Эксплойта нет | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .mzoom · meetings · CWE-295 | Критическая9,8 | — | 3,0 % | 27 сент. 2021 г. |
40В плане | CVE-2024-49369Proof of concept | Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connectionsicinga · icinga · CWE-295 | Критическая9,8 | — | 2,9 % | 12 нояб. 2024 г. |
40В плане | CVE-2020-1952Эксплойта нет | An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.apache · iotdb · CWE-295 | Критическая9,8 | — | 2,7 % | 27 апр. 2020 г. |
40В плане | CVE-2021-43882Эксплойта нет | Microsoft Defender for IoT Remote Code Execution Vulnerabilitymicrosoft · defender for iot · CWE-295 | Критическая9,8 | — | 2,4 % | 15 дек. 2021 г. |
40В плане | CVE-2023-26463Эксплойта нет | strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes witstrongswan · strongswan · CWE-295 | Критическая9,8 | — | 2,3 % | 14 апр. 2023 г. |
40В плане | CVE-2019-18847Эксплойта нет | Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.akamai · enterprise application access · CWE-295 | Критическая9,8 | — | 2,3 % | 26 авг. 2020 г. |
40В плане | CVE-2019-3777Эксплойта нет | Apps Manager unverified SSL certs in Cloud Controller proxypivotal software · application service · CWE-295 | Критическая9,8 | — | 1,9 % | 7 мар. 2019 г. |
40В плане | CVE-2016-1000030Эксплойта нет | Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutlpidgin · pidgin · CWE-295 | Критическая9,8 | — | 1,8 % | 5 сент. 2018 г. |
40В плане | CVE-2015-3886Эксплойта нет | libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown libinfinity project · libinfinity · CWE-295 | Критическая9,8 | — | 1,7 % | 21 июл. 2017 г. |
40В плане | CVE-2025-68121Эксплойта нет | Unexpected session resumption in crypto/tlsgolang · go · CWE-295 | Критическая10,0 | — | 0,9 % | 5 февр. 2026 г. |
40В плане | CVE-2024-5261Эксплойта нет | TLS certificate are not properly verified when utilizing LibreOfficeKitlibreoffice · libreoffice · CWE-295 | Критическая10,0 | — | 0,4 % | 25 июн. 2024 г. |
40В плане | CVE-2026-4370Эксплойта нет | Improper TLS Client/Server authentication and certificate verification on Database Clustercanonical · juju · CWE-295 | Критическая10,0 | — | 0,4 % | 1 апр. 2026 г. |
- CVE-2022-2692390Срочно
Active Directory Domain Services Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 84 %microsoft · windows 10 150710 мая 2022 г.
- CVE-2020-060189Срочно
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attac
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 89 %microsoft · windows 10 150714 янв. 2020 г.
- CVE-2026-8510271На этой неделе
Improper Certificate Validation in Quantum Security Gateway
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 8 %checkpoint · gaia embedded9 сент. 2026 г.
- CVE-2009-355565На этой неделе
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
КритическаяCVSS 9,8Proof of conceptEPSS 87 %apache · http server9 нояб. 2009 г.
- CVE-2023-2096361На этой неделе
In WorkSource, there is a possible parcel mismatch.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %google · android24 мар. 2023 г.
- CVE-2023-4199156В плане
A certificate validation issue was addressed.
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 13 %apple · ipados21 сент. 2023 г.
- CVE-2022-4297942В плане
Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ov
ВысокаяCVSS 8,8Эксплойта нетEPSS 24 %rydesharing · ryde6 янв. 2023 г.
- CVE-2017-280042В плане
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif
КритическаяCVSS 9,8Proof of conceptEPSS 9 %wolfssl · wolfssl24 мая 2017 г.
- CVE-2018-1282941В плане
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %adobe · creative cloud29 авг. 2018 г.
- CVE-2018-499140В плане
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %adobe · creative cloud19 мая 2018 г.
- CVE-2015-232040В плане
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %mono-project · mono8 янв. 2018 г.
- CVE-2020-2890740В плане
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via ve
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nagios · fusion24 мая 2021 г.
- CVE-2018-2102940В плане
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %systemd project · systemd30 окт. 2019 г.
- CVE-2021-3390740В плане
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %zoom · meetings27 сент. 2021 г.
- CVE-2024-4936940В плане
Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
КритическаяCVSS 9,8Proof of conceptEPSS 3 %icinga · icinga12 нояб. 2024 г.
- CVE-2020-195240В плане
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %apache · iotdb27 апр. 2020 г.
- CVE-2021-4388240В плане
Microsoft Defender for IoT Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microsoft · defender for iot15 дек. 2021 г.
- CVE-2023-2646340В плане
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes wit
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %strongswan · strongswan14 апр. 2023 г.
- CVE-2019-1884740В плане
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %akamai · enterprise application access26 авг. 2020 г.
- CVE-2019-377740В плане
Apps Manager unverified SSL certs in Cloud Controller proxy
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pivotal software · application service7 мар. 2019 г.
- CVE-2016-100003040В плане
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pidgin · pidgin5 сент. 2018 г.
- CVE-2015-388640В плане
libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %libinfinity project · libinfinity21 июл. 2017 г.
- CVE-2025-6812140В плане
Unexpected session resumption in crypto/tls
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %golang · go5 февр. 2026 г.
- CVE-2024-526140В плане
TLS certificate are not properly verified when utilizing LibreOfficeKit
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %libreoffice · libreoffice25 июн. 2024 г.
- CVE-2026-437040В плане
Improper TLS Client/Server authentication and certificate verification on Database Cluster
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %canonical · juju1 апр. 2026 г.