CWE-296—Improper Following of a Certificate's Chain of Trust
PUBLISHEDweakness recordLow
released 2006-07-19 · last modified 2026-04-30
Metadata
- CWE ID:
- CWE-296
- 摘要:
- Base
- 结构:
- Simple
- 状态:
- Draft
- 发布日期:
- 2006-07-19
- 更新日期:
- 2026-04-30
名称
Improper Following of a Certificate's Chain of Trust
描述
The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate.
There are several ways in which the chain of trust might be broken, including but not limited to:
常见后果
- 范围:
- Non-Repudiation
- 影响:
- Hide Activities
- 注释:
- Exploitation of this flaw can lead to the trust of data that may have originated with a spoofed source.
- 范围:
- Integrity, Confidentiality, Availability, Access Control
- 影响:
- Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands
- 注释:
- Data, requests, or actions taken by the attacking entity can be carried out as a spoofed benign entity.