MEDIUM · 6.0

CVE-2008-5082

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enro...

Vulnerability Description

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass intended authentication policies by performing enrollment with a software key.

CVSS Score

6.0

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Redhat Dogtag Certificate System1.0
RedhatCertificate System7.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-5082?

CVE-2008-5082 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enro...

How severe is CVE-2008-5082?

CVE-2008-5082 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-5082?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Dogtag Certificate System, Redhat Certificate System.