5.8

CVE-2009-5138

Exploit

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates, a different vulnerability than CVE-2014-1959.

Data is provided by the National Vulnerability Database (NVD)
GnuGnutls Version <= 2.7.5
GnuGnutls Version2.7.0
GnuGnutls Version2.7.1
GnuGnutls Version2.7.2
GnuGnutls Version2.7.3
GnuGnutls Version2.7.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.37% 0.784
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N