A04:2025: Cryptographic Failures
Weak crypto, missing crypto, plaintext sensitive data, weak key management.
How it's found
Found by inspecting TLS configuration, cipher suites, certificate validity, and transmission of sensitive data for cleartext or weak cryptographic handling.
Standards mapping
- References
- https://owasp.org/Top10/2025/
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Use of a Broken or Risky Cryptographic Algorithm using testssl.sh to check the live TLS configuration for deprecated protocol versions (SSLv3, TLS 1.0/1.1) and broken ciphers, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 12 dedicated rules for this weakness.
Tools: testssl.sh
Frequently asked questions
What is A04:2025 Cryptographic Failures?
Weak crypto, missing crypto, plaintext sensitive data, weak key management.
How do you find Cryptographic Failures?
Found by inspecting TLS configuration, cipher suites, certificate validity, and transmission of sensitive data for cleartext or weak cryptographic handling.
Which CWEs map to A04:2025?
A04:2025 maps to CWE-327, CWE-321, CWE-319.
Does TurboPentest test for Cryptographic Failures?
TurboPentest's automated black-box pentest actively probes for Use of a Broken or Risky Cryptographic Algorithm using testssl.sh to check the live TLS configuration for deprecated protocol versions (SSLv3, TLS 1.0/1.1) and broken ciphers, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 12 dedicated rules for this weakness.
Related OWASP categories
- OWASP Top 10 (Web)A01:2025: Broken Access Control
- OWASP Top 10 (Web)A02:2025: Security Misconfiguration
- OWASP Top 10 (Web)A03:2025: Software Supply Chain Failures
- OWASP Top 10 (Web)A05:2025: Injection
- OWASP Top 10 (Web)A06:2025: Insecure Design
- OWASP Top 10 (Web)A07:2025: Identification and Authentication Failures
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest