Improper Validation of Host-specific Certificate Data |
Weakness ID: 297 (Weakness Base) | Status: Incomplete |
Description Summary
Scope | Effect |
---|---|
Integrity | The data read from the system vouched for by the certificate may not be from the expected system. |
Authentication | Trust afforded to the system in question -- based on the expired certificate -- may allow for spoofing or redirection attacks. |
Example 1
Phase: Architecture and Design Check for expired certificates and provide the user with adequate information about the nature of the problem and how to proceed. |
If the host-specific data contained in a certificate is not checked, it may be possible for a redirection or spoofing attack to allow a malicious host with a valid certificate to provide data, impersonating a trusted host. While the attacker in question may have a valid certificate, it may simply be a valid certificate for a different site. In order to ensure data integrity, we must check that the certificate is valid and that it pertains to the site that we wish to access. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 295 | Certificate Issues | Development Concepts (primary)699 |
ChildOf | ![]() | 345 | Insufficient Verification of Data Authenticity | Research Concepts (primary)1000 |
ChildOf | ![]() | 754 | Improper Check for Unusual or Exceptional Conditions | Research Concepts1000 |
PeerOf | ![]() | 296 | Improper Following of Chain of Trust for Certificate Validation | Research Concepts1000 |
PeerOf | ![]() | 298 | Improper Validation of Certificate Expiration | Research Concepts1000 |
PeerOf | ![]() | 299 | Improper Check for Certificate Revocation | Research Concepts1000 |
ParentOf | ![]() | 599 | Trust of OpenSSL Certificate Without Validation | Development Concepts (primary)699 Research Concepts (primary)1000 |
PeerOf | ![]() | 370 | Missing Check for Certificate Revocation after Initial Check | Research Concepts1000 |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
CLASP | Failure to validate host-specific certificate data |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
CLASP | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Common Consequences, Relationships, Other Notes, Taxonomy Mappings | ||||
2009-03-10 | CWE Content Team | MITRE | Internal | |
updated Description, Name, Relationships | ||||
2009-05-27 | CWE Content Team | MITRE | Internal | |
updated Demonstrative Examples | ||||
2009-07-27 | CWE Content Team | MITRE | Internal | |
updated Demonstrative Examples, Relationships | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2009-03-10 | Failure to Validate Host-specific Certificate Data | |||