Cyber Posture

CWE · MITRE source

CWE-295Improper Certificate Validation

Abstraction: Base · CVEs in our corpus: 1,362

The product does not validate, or incorrectly validates, a certificate.

Last updated: 19 May 2026 13:12 UTC

NIST 800-53 r5 controls that address this weakness (3)AI

Control Title Family Why it addresses this CWE
SC-17Public Key Infrastructure CertificatesSCMandates approved trust anchors and issuance policies, directly preventing acceptance of unvalidated or untrusted certificates.
SC-45System Time SynchronizationSCCorrect system time is required for proper enforcement of certificate notBefore/notAfter dates and time-based revocation checks.
SA-19Component AuthenticitySAWhen certificates are used to establish component provenance, the control requires correct certificate validation procedures.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-0601 KEV9.38.10.94092020-01-14
CVE-2022-26923 KEV9.28.80.91442022-05-10
CVE-2015-3152 UPD4.35.90.51672016-05-16
CVE-2022-20703 KEV4.110.00.02002022-02-10
CVE-2024-290504.08.40.38302024-04-09
CVE-2023-20963 KEV3.77.80.01842023-03-24
CVE-2024-493693.49.80.24072024-11-12
CVE-2023-41991 KEV3.35.50.03902023-09-21
CVE-2020-82892.87.80.20542020-12-27
CVE-2023-264632.79.80.11542023-04-15
CVE-2014-12662.67.40.17902014-02-22
CVE-2017-2800 UPD2.59.80.08892017-05-24
CVE-2017-11770 UPD2.37.50.13682017-11-15
CVE-2023-424252.39.80.04952023-10-31
CVE-2015-23202.29.80.04832018-01-08
CVE-2018-80342.27.50.11722018-08-01
CVE-2021-339072.29.80.03252021-09-27
CVE-2023-278232.29.80.03942023-05-12
CVE-2012-2993 UPD2.15.90.14692012-09-18
CVE-2018-49912.19.80.02162018-05-19
CVE-2018-210292.19.80.01562019-10-30
CVE-2020-19522.19.80.01652020-04-27
CVE-2019-188472.19.80.02612020-08-26
CVE-2022-477582.19.80.01642023-04-27
CVE-2024-200802.19.80.02362024-07-01