CVE-2008-5082Improper Authentication in Redhat Certificate System

Severity
6.0MEDIUMNVD
EPSS
0.2%
top 58.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateMay 17

Description

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass intended authentication policies by performing enrollment with a software key.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-j872-hj4c-mqf5: The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 72022-05-17
CVEList
CVE-2008-5082: The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 72009-01-30

📋Vendor Advisories

1
Red Hat
System: missing public key challenge proof verification in the TPS component2009-01-29

💬Community

1
Bugzilla
CVE-2008-5082 Certificate System: missing public key challenge proof verification in the TPS component2008-12-11
CVE-2008-5082 — Improper Authentication in Redhat | cvebase