CWE-296
AllowedImproper Following of a Certificate's Chain of Trust
Abstraction: Base · Status: Draft
The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate.
32 vulnerabilities reference this CWE, most recent first.
GHSA-MQV2-J79J-4GQF
Vulnerability from github – Published: 2021-11-19 00:00 – Updated: 2024-02-27 18:44Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior versions.
{
"affected": [],
"aliases": [
"CVE-2021-23155"
],
"database_specific": {
"cwe_ids": [
"CWE-295",
"CWE-296"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-11-18T18:15:00Z",
"severity": "MODERATE"
},
"details": "Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior versions.",
"id": "GHSA-mqv2-j79j-4gqf",
"modified": "2024-02-27T18:44:57Z",
"published": "2021-11-19T00:00:29Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-23155"
},
{
"type": "WEB",
"url": "https://security.gallagher.com/Security-Advisories/CVE-2021-23155"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-MW8V-5VG6-VWX7
Vulnerability from github – Published: 2026-08-20 06:32 – Updated: 2026-08-20 06:32Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
{
"affected": [],
"aliases": [
"CVE-2026-73542"
],
"database_specific": {
"cwe_ids": [
"CWE-296"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-20T06:17:13Z",
"severity": "MODERATE"
},
"details": "Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor\u0027s information.",
"id": "GHSA-mw8v-5vg6-vwx7",
"modified": "2026-08-20T06:32:27Z",
"published": "2026-08-20T06:32:27Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73542"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU91609598"
},
{
"type": "WEB",
"url": "https://www.epson.jp/news/info/a-security202608.htm"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
Mitigation
Ensure that proper certificate checking is included in the system design.
Mitigation
Understand, and properly implement all checks necessary to ensure the integrity of certificate trust integrity.
Mitigation
If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the full chain of trust.
No CAPEC attack patterns related to this CWE.