Skip to main content

Self signed certificate

Plugin details

SeverityMedium
ID10010
CategoryAuthentication
CVSS score5.4
CVSS linkhttps://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Synopsis

The server can be accessed using unauthorized applications.

Description

The server trusts client applications with self-signed certificates. With this setting, application authentication is effectively disabled. Without application authentication, the server can be accessed using unauthorized applications.

Solution

Only trust certificates signed by a trusted authority.

References