Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24476
HistoryApr 10, 2020 - 12:55 a.m.

Spoofing Attacks

2020-04-1000:55:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.012 Low

EPSS

Percentile

85.1%

pki is vulnerable to spoofing attacks. The certificate authority used the MD5 hash algorithm to sign all SCEP protocol responses. As MD5 is not collision resistant, an attacker could use this flaw to perform an MD5 chosen-prefix collision attack to generate attack-chosen output signed using the certificate authority’s key.

References