VariantDraft
CWE-298Improper Validation of Certificate Expiration
Category: other
Description
A certificate expiration is not validated or is incorrectly validated.
Common consequences· 2
- Integrity / Other — OtherThe data read from the system vouched for by the expired certificate may be flawed due to malicious spoofing.
- Authentication / Other — OtherTrust may be assigned to certificates that have been abandoned due to age.
Potential mitigations· 2
- [Architecture and Design]Check for expired certificates and provide the user with adequate information about the nature of the problem and how to proceed.
- [Implementation]If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the expiration.
References
(incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-67108cve-2025-67108 | 0% | live |
| Vulnerability | CVE-2025-67109cve-2025-67109 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.