Improper Check for Certificate Revocation |
Weakness ID: 299 (Weakness Base) | Status: Draft |
Description Summary
Scope | Effect |
---|---|
Authentication | Trust may be assigned to an entity who is not who it claims to be. |
Integrity | Data from an untrusted (and possibly malicious) source may be integrated. |
Confidentiality | Date may be disclosed to an entity impersonating a trusted entity, resulting in information disclosure. |
Example 1
Phase: Architecture and Design Ensure that certificates are checked for revoked status. |
The failure to check for certificate revocation is a far more serious flaw than related certificate failures. This is because the use of any revoked certificate is almost certainly malicious. The most common reason for certificate revocation is compromise of the system in question, with the result that no legitimate servers will be using a revoked certificate, unless they are sorely out of sync. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 295 | Certificate Issues | Development Concepts (primary)699 |
ChildOf | ![]() | 404 | Improper Resource Shutdown or Release | Research Concepts (primary)1000 |
ChildOf | ![]() | 754 | Improper Check for Unusual or Exceptional Conditions | Research Concepts1000 |
PeerOf | ![]() | 296 | Improper Following of Chain of Trust for Certificate Validation | Research Concepts1000 |
PeerOf | ![]() | 297 | Improper Validation of Host-specific Certificate Data | Research Concepts1000 |
PeerOf | ![]() | 298 | Improper Validation of Certificate Expiration | Research Concepts1000 |
PeerOf | ![]() | 322 | Key Exchange without Entity Authentication | Research Concepts1000 |
ParentOf | ![]() | 370 | Missing Check for Certificate Revocation after Initial Check | Development Concepts (primary)699 Research Concepts (primary)1000 |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
CLASP | Failure to check for certificate revocation |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
CLASP | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Common Consequences, Relationships, Other Notes, Taxonomy Mappings | ||||
2009-03-10 | CWE Content Team | MITRE | Internal | |
updated Description, Name, Relationships | ||||
2009-05-27 | CWE Content Team | MITRE | Internal | |
updated Relationships | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2009-03-10 | Failure to Check for Certificate Revocation | |||