SFP Secondary Cluster: Digital Certificate
A category in the Common Weakness Enumeration published by The MITRE Corporation.
Categories in the Common Weakness Enumeration (CWE) group entries based on some common characteristic or attribute.
This category identifies Software Fault Patterns (SFPs) within the Digital Certificate cluster.
The software modifies the SSL context after connection creation has begun.
The software does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised.
The software does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate, resulting in incorrect trust of any reso...
A certificate expiration is not validated or is incorrectly validated, so trust may be assigned to certificates that have been abandoned due to age.
The software communicates with a host that provides a certificate, but the software does not properly ensure that the certificate is actually associated with that host.
The software uses OpenSSL and trusts or uses a certificate without using the SSL_get_verify_result() function to ensure that the certificate satisfies all necessary se...
CWE identifiers in this view are associated with clusters of Software Fault Patterns (SFPs).