5.8
CVSSv2

CVE-2010-3868

Published: 17/11/2010 Updated: 18/11/2010
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote malicious users to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat certificate system 7.3

redhat certificate system 8

redhat dogtag certificate system