CVE Vulnerabilities

CVE-2017-7537

DEPRECATED: Authentication Bypass Issues

Published: Jul 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing certificates.

Weakness

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linux_desktopRedhat7.0 (including)7.0 (including)
Enterprise_linux_serverRedhat7.0 (including)7.0 (including)
Enterprise_linux_workstationRedhat7.0 (including)7.0 (including)
Red Hat Enterprise Linux 7RedHatpki-core-0:10.4.1-11.el7*
Dogtag-pkiUbuntuartful*
Dogtag-pkiUbuntuesm-apps/xenial*
Dogtag-pkiUbuntuupstream*
Dogtag-pkiUbuntuxenial*
Dogtag-pkiUbuntuzesty*

References