CVE-2010-3868

Red Hat Certificate System 7.3 and 8 and Dogtag Certificate System - Unauthenticated SCEP One-Time PIN Disclosure

Title source: llm
STIX 2.1

Description

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0837.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/69149
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=648882
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0838.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024697
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42181

Scores

EPSS 0.0128
EPSS Percentile 66.5%

Details

CWE
CWE-287
Status published
Products (3)
redhat/certificate_system 7.3
redhat/certificate_system 8
redhat/dogtag_certificate_system
Published Nov 17, 2010
Tracked Since Feb 18, 2026