Cyber Resilience

CWE · MITRE source

CWE-599Missing Validation of OpenSSL Certificate

Abstraction: Variant · CVEs in our corpus: 14

The product uses OpenSSL and trusts or uses a certificate without using the SSL_get_verify_result() function to ensure that the certificate satisfies all necessary security requirements.

Last updated: 20 August 2026 14:15 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.DS-02
  • PR.PS-06
  • PR.AA-03
  • IA-5 Authenticator Management
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V12.3.5
  • V17.2.8

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-12553 7.19.80.00212025-10-31
CVE-2024-40464 6.68.80.00572024-07-31
CVE-2021-21374 6.18.10.01042021-03-26
CVE-2022-31105 6.08.30.00772022-07-12
CVE-2026-25060 6.08.10.00242026-02-02
CVE-2024-41265 5.77.50.00262024-08-01
CVE-2025-56230 5.77.50.00222025-11-04
CVE-2023-48052 5.67.40.00312023-11-16
CVE-2024-41253 5.17.10.00122024-07-31
CVE-2024-36755 5.06.80.00132024-06-27
CVE-2025-56232 5.06.80.00122025-11-05
CVE-2025-56146 4.25.30.00152025-09-23
CVE-2025-634323.74.60.00172025-11-24