CVE-2011-4197: High severity pfsense vulnerability
Published Jan 3, 2012
·Updated
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.
Affected Software
5 affected components
pfSense pfSense<=2.0
pfSense pfSense=1.2.1
pfSense pfSense=1.0.x
pfSense pfSense=1.2.2
pfSense pfSense=1.2.3
Event History
Jan 3, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4197?
CVE-2011-4197 has a high severity rating due to the potential for remote attackers to create sub-certificates.
2
How do I fix CVE-2011-4197?
To fix CVE-2011-4197, upgrade pfSense to version 2.0.1 or later.
3
What versions of pfSense are affected by CVE-2011-4197?
CVE-2011-4197 affects pfSense versions prior to 2.0.1, including 1.0.x, 1.2.1, 1.2.2, and 1.2.3.
4
What does CVE-2011-4197 exploit?
CVE-2011-4197 exploits the incorrect handling of CA basic constraints in X.509 certificates.
5
Can CVE-2011-4197 be exploited without authentication?
Yes, CVE-2011-4197 can be exploited by remote attackers without requiring authentication.