CVE-2007-5810
published 2007-11-05CVE-2007-5810: Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
0.78%
51.7th percentile
Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachi | cosminexus_application_server_enterprise | <= 06_51_j | — |
| hitachi | cosminexus_application_server_standard | <= 06_51_j | — |
| hitachi | cosminexus_developer_light_version_6 | <= 06_51_j | — |
| hitachi | cosminexus_developer_professional_version_6 | <= 06_51_j | — |
| hitachi | cosminexus_developer_standard_version_6 | <= 06_51_j | — |
| hitachi | cosminexus_server | <= 04_01 | — |
| hitachi | ucosminexus_application_server_enterprise | <= 07_50_01 | — |
| hitachi | ucosminexus_application_server_standard | <= 07_50_01 | — |
| hitachi | ucosminexus_developer_light | <= 06_71_d | — |
| hitachi | ucosminexus_developer_professional | <= 07_50_01 | — |
| hitachi | ucosminexus_developer_standard | <= 07_50_01 | — |
| hitachi | ucosminexus_service_architect | <= 07_50_01 | — |
| hitachi | ucosminexus_service_platform | <= 07_50_01 | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
| hitachi | web_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
OpenSSL RSA Signature Forgery Vulnerability
vendor_cisco·2006-09-05·CVSS 5.0
CVE-2007-5810 [MEDIUM] OpenSSL RSA Signature Forgery Vulnerability
OpenSSL RSA Signature Forgery Vulnerability
OpenSSL versions 0.9.7j and prior and 0.9.8b and prior contain a vulnerability that could allow an unauthenticated, remote attacker to successfully pass a forged X.509 certificate.
The vulnerability could allow an unauthenticated, remote attacker to pass a forged Public-Key Cryptography Standards (PKCS)#1 Version 1.5 signature when signed by a certain type of RSA key. An attacker could exploit the vulnerability to access certificate-protected resources.
OpenSSL confirmed the vulnerability in a security advisory and released updated versions.
This vulnerability affects PKCS #1 v1.5 signatures if the exponent of the public key is 3, which is widely used by Certificate Authorities. An attacker will likely exploit this vulnerability to forge signa
GHSA
GHSA-cfg9-hj54-h2q5: Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might all
ghsa_unreviewed·2022-05-01
CVE-2007-5810 [MEDIUM] CWE-20 GHSA-cfg9-hj54-h2q5: Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might all
Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/42026http://secunia.com/advisories/27421http://www.hitachi-support.com/security_e/vuls_e/HS07-034_e/index-e.htmlhttp://www.securityfocus.com/bid/26271http://www.vupen.com/english/advisories/2007/3666http://osvdb.org/42026http://secunia.com/advisories/27421http://www.hitachi-support.com/security_e/vuls_e/HS07-034_e/index-e.htmlhttp://www.securityfocus.com/bid/26271http://www.vupen.com/english/advisories/2007/3666
2007-11-05
Published