ZeroHour

CVE-2017-7537

PoC
CVSS 3.0
7.5 high
EPSS
1%p72
Published
()
Modified
Description

It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing certificates.

Vendors
redhatdogtagpki
Products
enterprise linux desktop, enterprise linux server, enterprise linux workstation, dogtagpki
Weakness
CWE-592, CWE-798
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.