CVE-2010-3868
published 2010-11-17CVE-2010-3868: Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which…
PriorityP430medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.28%
66.9th percentile
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | certificate_system | — | — |
| redhat | certificate_system | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hg35-p8x7-fw5f: Red Hat Certificate System (RHCS) 7
ghsa_unreviewed·2022-05-17
CVE-2010-3868 [MEDIUM] CWE-287 GHSA-hg35-p8x7-fw5f: Red Hat Certificate System (RHCS) 7
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.
Red Hat
System: unauthenticated user can request SCEP one-time PIN decryption
vendor_redhat·2010-11-08·CVSS 5.8
CVE-2010-3868 [MEDIUM] System: unauthenticated user can request SCEP one-time PIN decryption
System: unauthenticated user can request SCEP one-time PIN decryption
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/42181http://securitytracker.com/id?1024697http://www.osvdb.org/69149https://bugzilla.redhat.com/show_bug.cgi?id=648882https://fedorahosted.org/pki/changeset/1261https://rhn.redhat.com/errata/RHSA-2010-0837.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0838.htmlhttp://secunia.com/advisories/42181http://securitytracker.com/id?1024697http://www.osvdb.org/69149https://bugzilla.redhat.com/show_bug.cgi?id=648882https://fedorahosted.org/pki/changeset/1261https://rhn.redhat.com/errata/RHSA-2010-0837.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0838.html
2010-11-17
Published