The product does not correctly validate a certificate chain, host name, or expiry.
Use platform TLS validation as-is; never disable verification, pin only with rotation plans.
MITRE ATT&CK techniques associated with this weakness class (mapped via MITRE CAPEC). A vulnerability of this type could let an adversary carry out: