Lucene search

K
cveMitreCVE-2003-0960
HistoryDec 15, 2003 - 5:00 a.m.

CVE-2003-0960

2003-12-1505:00:00
mitre
web.nvd.nist.gov
40
openca
certificate
chain
serial
check
security
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

52.8%

OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.

Affected configurations

Nvd
Node
opencaopencaMatch0.8.0
OR
opencaopencaMatch0.8.1
OR
opencaopencaMatch0.8.6
OR
opencaopencaMatch0.9.0
OR
opencaopencaMatch0.9.0.1
OR
opencaopencaMatch0.9.0.2
OR
opencaopencaMatch0.9.1
OR
opencaopencaMatch0.9.1.2
OR
opencaopencaMatch0.9.1.3
VendorProductVersionCPE
opencaopenca0.8.0cpe:2.3:a:openca:openca:0.8.0:*:*:*:*:*:*:*
opencaopenca0.8.1cpe:2.3:a:openca:openca:0.8.1:*:*:*:*:*:*:*
opencaopenca0.8.6cpe:2.3:a:openca:openca:0.8.6:*:*:*:*:*:*:*
opencaopenca0.9.0cpe:2.3:a:openca:openca:0.9.0:*:*:*:*:*:*:*
opencaopenca0.9.0.1cpe:2.3:a:openca:openca:0.9.0.1:*:*:*:*:*:*:*
opencaopenca0.9.0.2cpe:2.3:a:openca:openca:0.9.0.2:*:*:*:*:*:*:*
opencaopenca0.9.1cpe:2.3:a:openca:openca:0.9.1:*:*:*:*:*:*:*
opencaopenca0.9.1.2cpe:2.3:a:openca:openca:0.9.1.2:*:*:*:*:*:*:*
opencaopenca0.9.1.3cpe:2.3:a:openca:openca:0.9.1.3:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

52.8%