CWE-295
Improper Certificate Validation
About
The product does not validate, or incorrectly validates, a certificate.
Common consequences
- Integrity, Authentication → Bypass Protection Mechanism, Gain Privileges or Assume Identity
Mitigations
- Architecture and Design, Implementation: Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.
- Implementation: If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.
CVEs with this weakness
Frequently asked questions
What is CWE-295?
The product does not validate, or incorrectly validates, a certificate. Common consequences Integrity, Authentication → Bypass Protection Mechanism, Gain Privileges or Assume Identity Mitigations Architecture and Design, Implementation: Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.
Which platforms does CWE-295 affect?
CWE-295 has been observed on: Not Technology-Specific, Web Based, Mobile.
How many CVEs does Rainforest track for CWE-295?
Rainforest Labs currently tracks 1 published CVEs mapped to CWE-295. They are listed on this page.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
