Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-3868

Опубликовано: 17 нояб. 2010
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:certificate_system:7.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:certificate_system:8:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:redhat:dogtag_certificate_system:*:*:*:*:*:*:*:*

EPSS

Процентиль: 51%
0.00277
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

redhat
около 15 лет назад

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

github
больше 3 лет назад

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

EPSS

Процентиль: 51%
0.00277
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-287