CVE-2010-3868

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:certificate_system:7.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:certificate_system:8:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:dogtag_certificate_system:*:*:*:*:*:*:*:*

Information

Published : 2010-11-17 08:00

Updated : 2010-11-17 21:00


NVD link : CVE-2010-3868

Mitre link : CVE-2010-3868


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

redhat

  • certificate_system
  • dogtag_certificate_system