CVE-2010-3868 Information

Description

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

Reference

http://secunia.com/advisories/42181 http://securitytracker.com/id?1024697 http://www.osvdb.org/69149 https://bugzilla.redhat.com/show_bug.cgi?id=648882 https://fedorahosted.org/pki/changeset/1261 https://rhn.redhat.com/errata/RHSA-2010-0837.html https://rhn.redhat.com/errata/RHSA-2010-0838.html

Share on: