CWE-295

CWE-295 là gì?

Đang phân tích dữ liệu...

Thống kê dữ liệu

THỨ HẠNG OWASP TOP 10:20257A07:2025 — Authentication Failures
TỔNG SỐ CVE LIÊN QUAN (365 NGÀY)188
MỨC TRỪU TƯỢNGCơ bản

Số lượng lỗ hổng nằm trong CWE-295

188 lỗ hổngTăng 229,8% so với cùng kỳ

Số lượng lỗ hổng trong CISA KEV của CWE-295

0 lỗ hổng

Định nghĩa chính thức

TheoMitre CWE

Đặc điểm

Dữ liệu MITRE CWE chính thức

Giai đoạn hình thành

  • Kiến trúc và thiết kế
  • Hiện thực hóa: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
  • Hiện thực hóa: When the product uses certificate pinning, the developer might not properly validate all relevant components of the certificate before pinning the certificate. This can make it difficult or expensive to test after the pinning is complete.

Hậu quả thường gặp

Dữ liệu MITRE CWE chính thức
Tác độngPhạm viDiễn giải
Vượt qua cơ chế bảo vệ, Chiếm đặc quyền hoặc mạo danhTính toàn vẹn, Xác thựcWhen a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The product might connect to a malicious host while believing it is a trusted host, or the product might be deceived into accepting spoofed data that appears to originate from a trusted host.

Biện pháp giảm thiểu rủi ro

Dữ liệu MITRE CWE chính thức
  1. Kiến trúc và thiết kế, Hiện thực hóaCertificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.
  2. Hiện thực hóaIf certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.

Cách phát hiện trong hệ thống

Dữ liệu MITRE CWE chính thức
Phương phápCách làmHiệu quả
Phân tích tĩnh tệp nhị phân hoặc bytecode tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Bytecode Weakness Analysis - including disassembler + source code weakness analysis Binary Weakness Analysis - including disassembler + source code weakness analysisSOAR một phần
Phân tích tĩnh tệp nhị phân hoặc bytecode thủ côngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomaliesSOAR một phần
Phân tích động với diễn giải kết quả tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Web Application ScannerSOAR một phần
Phân tích động với diễn giải kết quả thủ côngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Man-in-the-middle attack toolCao
Phân tích tĩnh mã nguồn thủ côngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)Cao
Phân tích tĩnh mã nguồn tự độngAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Source code Weakness Analyzer Context-configured Source Code Weakness AnalyzerSOAR một phần
Rà soát kiến trúc hoặc thiết kếAccording to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)Cao

Lỗ hổng điển hình

Dữ liệu MITRE CWE chính thức

Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-295, dựa theo mức độ ưu tiên

Nguồn (4)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan