Lucene search

K
cveRedhatCVE-2008-5082
HistoryJan 30, 2009 - 7:30 p.m.

CVE-2008-5082

2009-01-3019:30:00
CWE-287
redhat
web.nvd.nist.gov
29
cve-2008-5082
token processing system
rhcs
dogtag certificate system
authentication bypass
remote

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.005

Percentile

75.7%

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass intended authentication policies by performing enrollment with a software key.

Affected configurations

Nvd
Node
redhat_dogtag_certificate_systemMatch1.0
OR
redhatcertificate_systemMatch7.1
OR
redhatcertificate_systemMatch7.2
OR
redhatcertificate_systemMatch7.3
VendorProductVersionCPE
redhat_dogtag_certificate_system1.0cpe:2.3:a:redhat:_dogtag_certificate_system:1.0:*:*:*:*:*:*:*
redhatcertificate_system7.1cpe:2.3:a:redhat:certificate_system:7.1:*:*:*:*:*:*:*
redhatcertificate_system7.2cpe:2.3:a:redhat:certificate_system:7.2:*:*:*:*:*:*:*
redhatcertificate_system7.3cpe:2.3:a:redhat:certificate_system:7.3:*:*:*:*:*:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.005

Percentile

75.7%

Related for CVE-2008-5082