Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1676

Опубликовано: 07 июл. 2008
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:redhat:certificate_system:7.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:certificate_system:7.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:certificate_system:7.3:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:netscape:certificate_management_system:*:*:*:*:*:*:*:*
Версия до 6.2 (включая)
cpe:2.3:a:netscape:certificate_management_system:6.0:*:*:*:*:*:*:*
cpe:2.3:a:netscape:certificate_management_system:6.01:*:*:*:*:*:*:*
cpe:2.3:a:netscape:certificate_management_system:6.1:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00257
Низкий

7.5 High

CVSS2

Дефекты

CWE-255

Связанные уязвимости

redhat
около 17 лет назад

Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.

github
больше 3 лет назад

Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.

EPSS

Процентиль: 49%
0.00257
Низкий

7.5 High

CVSS2

Дефекты

CWE-255