Описание
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
A flaw was found in Step CA, an online certificate authority. A remote attacker can exploit this vulnerability by sending an unauthenticated SCEP (Simple Certificate Enrollment Protocol) Update Request. This allows the attacker to issue unauthorized certificates, potentially leading to a compromise of the certificate management system and enabling further attacks such as impersonation or man-in-the-middle attacks.
Отчет
No Red Hat products are impacted. The affected component (Step CA) is not used or provided by any products.
Ссылки на источники
Дополнительная информация
Статус:
EPSS
10 Critical
CVSS3
Связанные уязвимости
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
EPSS
10 Critical
CVSS3