7.5

CVE-2008-1676

Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetscapeCertificate Management System Version <= 6.2
   RedhatCertificate System Version7.1
   RedhatCertificate System Version7.2
   RedhatCertificate System Version7.3
NetscapeCertificate Management System Version6.0
   RedhatCertificate System Version7.1
   RedhatCertificate System Version7.2
   RedhatCertificate System Version7.3
NetscapeCertificate Management System Version6.01
   RedhatCertificate System Version7.1
   RedhatCertificate System Version7.2
   RedhatCertificate System Version7.3
NetscapeCertificate Management System Version6.1
   RedhatCertificate System Version7.1
   RedhatCertificate System Version7.2
   RedhatCertificate System Version7.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.462
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P