Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.
References
Information
Published : 2010-11-17 08:00
Updated : 2010-11-17 21:00
NVD link : CVE-2010-3868
Mitre link : CVE-2010-3868
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
redhat
- certificate_system
- dogtag_certificate_system