VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-3868
certificate_system, dogtag_certificate_system: Red Hat Certificate System (RHCS) 7.3 and 8 and Dog...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3868

Original

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-11-17
Source Information Category:
Advisory, Alert
Last Updated:
2010-11-18




Affected Product Tags
cpe:/a:redhat:certificate_system:7.3
cpe:/a:redhat:certificate_system:8
cpe:/a:redhat:dogtag_certificate_system
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

Alternatives




References
CONFIRM https://fedorahosted.org/pki/changeset/1261




CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=648882




OSVDB 69149




REDHAT RHSA-2010:0838




REDHAT RHSA-2010:0837




SECTRACK 1024697




SECUNIA 42181




Vulnerability Type Authentication Issues (CWE-287)





Copyright © 2010 JPCERT/CC All Rights Reserved.