6
CVSSv2

CVE-2008-5082

Published: 30/01/2009 Updated: 08/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 up to and including 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass intended authentication policies by performing enrollment with a software key.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat certificate system 7.1

redhat certificate system 7.2

redhat certificate system 7.3

redhat dogtag certificate system 1.0