CVE-2010-3868
Red Hat Certificate System 7.3 and 8 and Dogtag Certificate System - Unauthenticated SCEP One-Time PIN Disclosure
Title source: llmDescription
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.
References (7)
Core 7
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0837.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/69149
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=648882
Vendor Advisory vendor-advisory
x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0838.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1024697
Patch x_refsource_confirm
https://fedorahosted.org/pki/changeset/1261
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42181
Scores
EPSS
0.0128
EPSS Percentile
66.5%
Details
CWE
CWE-287
Status
published
Products (3)
redhat/certificate_system
7.3
redhat/certificate_system
8
redhat/dogtag_certificate_system
Published
Nov 17, 2010
Tracked Since
Feb 18, 2026