Common Weakness Enumeration

    CWE Definition / CWE-322

    CWE-322: Key Exchange without Entity Authentication

    The product performs a key exchange with an actor without verifying the identity of that actor.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-306: Missing Authentication for Critical Function

    CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

    CWE-295: Improper Certificate Validation