Lucene search

K
cveMitreCVE-2006-4991
HistorySep 26, 2006 - 2:07 a.m.

CVE-2006-4991

2006-09-2602:07:00
mitre
web.nvd.nist.gov
26
rsa
keonca
certificate authority
security vulnerability
audit logs
xml
integrity check
nvd

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

5.1%

RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity check function that operates on the entire pool, or (2) modifying entries in the live log file, which is only signed during rotation.

Affected configurations

Nvd
Node
rsakeon_certificate_authority_managerMatch6.5.1
OR
rsakeon_certificate_authority_managerMatch6.6
VendorProductVersionCPE
rsakeon_certificate_authority_manager6.5.1cpe:2.3:a:rsa:keon_certificate_authority_manager:6.5.1:*:*:*:*:*:*:*
rsakeon_certificate_authority_manager6.6cpe:2.3:a:rsa:keon_certificate_authority_manager:6.6:*:*:*:*:*:*:*

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2006-4991