CWE-1428— Reliance on HTTP instead of HTTPS
The product provides or relies on use of HTTP communications when HTTPS is available.— MITRE CWE catalog
2 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1428page 1 of 1
- CVE-2026-10763HIGHCVSS 7.0EG 7.02026-06-30
PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.
- CVE-2026-40677HIGHCVSS 7.7EG 7.72026-06-12
The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.
Map vulnerabilities like CWE-1428 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1428 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →