M5:2024: Insecure Communication
Network traffic sent without TLS, with weak cipher suites, or without certificate/public-key pinning, allowing interception or tampering in transit.
How it's found
Found by inspecting network traffic for certificate pinning, cipher strength, and cleartext transmission of sensitive data.
Standards mapping
How TurboPentest tests for this (white-box)
This weakness (Improper Certificate Validation) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 8 rules for it, flagging the issue directly in your source code as part of the pentest.
Frequently asked questions
What is M5:2024 Insecure Communication?
Network traffic sent without TLS, with weak cipher suites, or without certificate/public-key pinning, allowing interception or tampering in transit.
How do you find Insecure Communication?
Found by inspecting network traffic for certificate pinning, cipher strength, and cleartext transmission of sensitive data.
Which CWEs map to M5:2024?
M5:2024 maps to CWE-295, CWE-319, CWE-296.
Does TurboPentest test for Insecure Communication?
This weakness (Improper Certificate Validation) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 8 rules for it, flagging the issue directly in your source code as part of the pentest.
Related OWASP categories
- OWASP Mobile Top 10M1:2024: Improper Credential Usage
- OWASP Mobile Top 10M2:2024: Inadequate Supply Chain Security
- OWASP Mobile Top 10M3:2024: Insecure Authentication/Authorization
- OWASP Mobile Top 10M4:2024: Insufficient Input/Output Validation
- OWASP Mobile Top 10M6:2024: Inadequate Privacy Controls
- OWASP Mobile Top 10M7:2024: Insufficient Binary Protections
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest