Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wprp-q629-mgxj

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.

etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.

EPSS

Процентиль: 75%
0.00902
Низкий

Связанные уязвимости

nvd
около 14 лет назад

etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.

EPSS

Процентиль: 75%
0.00902
Низкий