REDHAT-BUG-648883: Medium severity red hat certificate system vulnerability
Red Hat / Dogtag Certificate System did not prevent re-use of the one-time PIN used in the SCEP (Simple Certificate Enrollment Protocol) protocol enrollment requests. The check was done to ensure that PIN is valid, but the PIN was never removed from the list of valid PINs once it was used. An attacker possessing a valid SCEP enrollment one-time PIN could use it to generate an unlimited number of certificates.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-648883?
The severity of REDHAT-BUG-648883 is considered high due to the risk of unauthorized certificate issuance.
How do I fix REDHAT-BUG-648883?
To fix REDHAT-BUG-648883, upgrade to the latest patched version of Red Hat Dogtag Certificate System that addresses this vulnerability.
What systems are affected by REDHAT-BUG-648883?
REDHAT-BUG-648883 affects the Red Hat Dogtag Certificate System specifically.
What are the implications of REDHAT-BUG-648883?
The implications of REDHAT-BUG-648883 include potential exposure to unauthorized access to secure communications or data.
Is there a workaround for REDHAT-BUG-648883?
Currently, no effective workaround is available for REDHAT-BUG-648883; updating the software is recommended.