Back

MEDIUM

System: unauthenticated user can request SCEP one-time PIN decryption

Published Nov 17, 2010

Description

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

Affected products

Remediation

No remediation recorded yet.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 17, 2010
Updated Aug 7, 2024
Reserved Oct 8, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Nov 8, 2010
ENISA EUVD
Assigner redhat
Published Nov 17, 2010
Updated Aug 7, 2024
Exploited since n/a
EUVD-2010-3846