CVE-2010-3869
System: SCEP one-time PIN reuse
Severity Score
4.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN.
Red Hat Certificate System (RHCS) v7.3 y v8 y Dogtag Certificate System permiten a usuarios autenticados remotamente generar un número aleatorio de certificados mediante la sustitución de un único PIN SCEP one-time.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-10-08 CVE Reserved
- 2010-11-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1024697 | Vdb Entry | |
http://www.osvdb.org/69148 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fedorahosted.org/pki/changeset/1246 | 2010-11-18 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/42181 | 2010-11-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=648883 | 2010-11-08 | |
https://rhn.redhat.com/errata/RHSA-2010-0837.html | 2010-11-18 | |
https://rhn.redhat.com/errata/RHSA-2010-0838.html | 2010-11-18 | |
https://access.redhat.com/security/cve/CVE-2010-3869 | 2010-11-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Certificate System Search vendor "Redhat" for product "Certificate System" | 7.3 Search vendor "Redhat" for product "Certificate System" and version "7.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Certificate System Search vendor "Redhat" for product "Certificate System" | 8 Search vendor "Redhat" for product "Certificate System" and version "8" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Dogtag Certificate System Search vendor "Redhat" for product "Dogtag Certificate System" | * | - |
Affected
|