CWE-296 · 14 kayıt
Improper Following of a Certificate's Chain of Trust
Bu sınıftaki CVE’ler
14 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2025-48057İstismar yok | Icinga 2 certificate renewal might incorrectly renew an invalid certificateicinga · icinga · CWE-296 | Kritik9,3 | — | %0,4 | 27 May 2025 |
37İzleyin | CVE-2026-96770İstismar yok | s2s-proxy accepts untrusted client certificatestemporal technologies, inc. · s2s-proxy · CWE-296 | Kritik9,3 | — | %0,3 | 23 Eyl 2026 |
33İzleyin | CVE-2026-33779İstismar yok | Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communicationjuniper · junos · CWE-296 | Yüksek8,3 | — | %0,2 | 9 Nis 2026 |
33İzleyin | CVE-2026-24066İstismar yok | Slate Digital Connect macOS XPC certificate validation privilege escalationslate digital llc · slate digital connect · CWE-296 | Yüksek8,4 | — | %0,1 | 10 Haz 2026 |
32İzleyin | CVE-2021-23162İstismar yok | Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Cgallagher · command centre mobile connect · CWE-296 | Yüksek8,1 | — | %0,4 | 18 Kas 2021 |
32İzleyin | CVE-2025-1146İstismar yok | CrowdStrike Falcon Sensor for Linux TLS Issuecrowdstrike · falcon sensor for linux · CWE-296 | Yüksek8,1 | — | %0,3 | 12 Şub 2025 |
30İzleyin | CVE-2019-3762İstismar yok | Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability.dell · emc data protection central · CWE-296 | Yüksek7,5 | — | %0,6 | 18 Mar 2020 |
29İzleyin | CVE-2021-1566İstismar yok | Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerabilitycisco · email security appliance · CWE-296 | Yüksek7,4 | — | %0,7 | 16 Haz 2021 |
28İzleyin | CVE-2026-44852İstismar yok | Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interfacearubanetworks · arubaos · CWE-296 | Yüksek7,2 | — | %0,6 | 12 May 2026 |
27İzleyin | CVE-2021-23155İstismar yok | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Cegallagher · command centre mobile client · CWE-296 | Orta6,8 | — | %0,5 | 18 Kas 2021 |
25İzleyin | CVE-2026-73542İstismar yok | Multiple SEIKO EPSON printers and scanners contain revoked root certificates.seiko epson corporation · multiple seiko epson printers and scanners · CWE-296 | Orta6,3 | — | %0,2 | 20 Ağu 2026 |
24İzleyin | CVE-2021-44532İstismar yok | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format.nodejs · node.js · CWE-296 | Orta5,3 | — | %10,4 | 24 Şub 2022 |
19İzleyin | CVE-2025-22459İstismar yok | Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticateivanti · endpoint manager · CWE-296 | Orta4,8 | — | %0,3 | 8 Nis 2025 |
17İzleyin | CVE-2024-43196İstismar yok | IBM OpenPages data manipulationibm · openpages with watson · CWE-296 | Orta4,3 | — | %0,2 | 20 Şub 2025 |
- CVE-2025-4805737İzleyin
Icinga 2 certificate renewal might incorrectly renew an invalid certificate
KritikCVSS 9,3İstismar yokEPSS %0icinga · icinga27 May 2025
- CVE-2026-9677037İzleyin
s2s-proxy accepts untrusted client certificates
KritikCVSS 9,3İstismar yokEPSS %0temporal technologies, inc. · s2s-proxy23 Eyl 2026
- CVE-2026-3377933İzleyin
Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
YüksekCVSS 8,3İstismar yokEPSS %0juniper · junos9 Nis 2026
- CVE-2026-2406633İzleyin
Slate Digital Connect macOS XPC certificate validation privilege escalation
YüksekCVSS 8,4İstismar yokEPSS %0slate digital llc · slate digital connect10 Haz 2026
- CVE-2021-2316232İzleyin
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C
YüksekCVSS 8,1İstismar yokEPSS %0gallagher · command centre mobile connect18 Kas 2021
- CVE-2025-114632İzleyin
CrowdStrike Falcon Sensor for Linux TLS Issue
YüksekCVSS 8,1İstismar yokEPSS %0crowdstrike · falcon sensor for linux12 Şub 2025
- CVE-2019-376230İzleyin
Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability.
YüksekCVSS 7,5İstismar yokEPSS %1dell · emc data protection central18 Mar 2020
- CVE-2021-156629İzleyin
Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability
YüksekCVSS 7,4İstismar yokEPSS %1cisco · email security appliance16 Haz 2021
- CVE-2026-4485228İzleyin
Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interface
YüksekCVSS 7,2İstismar yokEPSS %1arubanetworks · arubaos12 May 2026
- CVE-2021-2315527İzleyin
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce
OrtaCVSS 6,8İstismar yokEPSS %0gallagher · command centre mobile client18 Kas 2021
- CVE-2026-7354225İzleyin
Multiple SEIKO EPSON printers and scanners contain revoked root certificates.
OrtaCVSS 6,3İstismar yokEPSS %0seiko epson corporation · multiple seiko epson printers and scanners20 Ağu 2026
- CVE-2021-4453224İzleyin
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format.
OrtaCVSS 5,3İstismar yokEPSS %10nodejs · node.js24 Şub 2022
- CVE-2025-2245919İzleyin
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticate
OrtaCVSS 4,8İstismar yokEPSS %0ivanti · endpoint manager8 Nis 2025
- CVE-2024-4319617İzleyin
IBM OpenPages data manipulation
OrtaCVSS 4,3İstismar yokEPSS %0ibm · openpages with watson20 Şub 2025