CWE-370: Missing Check for Certificate Revocation after Initial Check

low-risk

The product does not check the revocation status of a certificate after its initial revocation check, which can cause the product to perform privileged actions even after the certificate is revoked at a later time.

Abstraction: Variant

Common Consequences

Access Control Gain Privileges or Assume Identity
Integrity Modify Application Data
Confidentiality Read Application Data

Real-World Examples (1)

CVE CVSS EPSS KEV
CVE-2025-67108 10.0 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal