Cyber Posture

CWE · MITRE source

CWE-295Improper Certificate Validation

Abstraction: Base · CVEs in our corpus: 1,342

The product does not validate, or incorrectly validates, a certificate.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (3)AI

Control Title Family Why it addresses this CWE
SC-17Public Key Infrastructure CertificatesSCMandates approved trust anchors and issuance policies, directly preventing acceptance of unvalidated or untrusted certificates.
SC-45System Time SynchronizationSCCorrect system time is required for proper enforcement of certificate notBefore/notAfter dates and time-based revocation checks.
SA-19Component AuthenticitySAWhen certificates are used to establish component provenance, the control requires correct certificate validation procedures.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-0601 KEV9.38.10.94092020-01-14
CVE-2022-26923 KEV9.28.80.91442022-05-10
CVE-2015-31524.35.90.51672016-05-16
CVE-2022-20703 KEV4.110.00.02002022-02-10
CVE-2024-290504.08.40.38302024-04-09
CVE-2023-20963 KEV3.77.80.01842023-03-24
CVE-2024-493693.59.80.25512024-11-12
CVE-2023-41991 KEV3.35.50.03552023-09-21
CVE-2020-82892.87.80.20542020-12-27
CVE-2023-264632.79.80.11542023-04-15
CVE-2014-12662.67.40.17902014-02-22
CVE-2017-28002.59.80.08892017-05-24
CVE-2017-117702.37.50.13682017-11-15
CVE-2023-424252.39.80.04952023-10-31
CVE-2015-23202.29.80.04832018-01-08
CVE-2018-80342.27.50.11722018-08-01
CVE-2021-339072.29.80.03252021-09-27
CVE-2012-29932.15.90.14692012-09-18
CVE-2018-49912.19.80.02162018-05-19
CVE-2018-210292.19.80.01562019-10-30
CVE-2020-19522.19.80.01652020-04-27
CVE-2019-188472.19.80.02612020-08-26
CVE-2023-278232.19.80.01942023-05-12
CVE-2024-200802.19.80.02362024-07-01
CVE-2025-293312.19.80.01902025-06-26