CWE-296Improper Following of a Certificate's Chain of Trust

PUBLISHEDweakness recordLow
released 2006-07-19 · last modified 2026-04-30
CWE-296 - Improper Following of a Certificate's Chain of Trust - Diagram

Metadata

CWE ID:
CWE-296
摘要:
Base
结构:
Simple
状态:
Draft
发布日期:
2006-07-19
更新日期:
2026-04-30

名称

Improper Following of a Certificate's Chain of Trust

描述

The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate.

There are several ways in which the chain of trust might be broken, including but not limited to:

常见后果

范围:
Non-Repudiation
影响:
Hide Activities
注释:
Exploitation of this flaw can lead to the trust of data that may have originated with a spoofed source.
范围:
Integrity, Confidentiality, Availability, Access Control
影响:
Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands
注释:
Data, requests, or actions taken by the attacking entity can be carried out as a spoofed benign entity.

相关 CWE