Vulnerability Description
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pfsense | Pfsense | <= 2.0 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2011-12/0152.html
- http://secunia.com/advisories/46780Vendor Advisory
- http://www.osvdb.org/77982
- http://www.securityfocus.com/bid/51169
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71969
- https://github.com/bsdperimeter/pfsense/commit/1379d66f11aaf72982a70287b83e24efc
- https://github.com/bsdperimeter/pfsense/commit/87b4deb2b2dae9013e6aa0fe490d6a5a0
- https://www.trustmatta.com/advisories/MATTA-2011-001.txt
- http://archives.neohapsis.com/archives/bugtraq/2011-12/0152.html
- http://secunia.com/advisories/46780Vendor Advisory
- http://www.osvdb.org/77982
- http://www.securityfocus.com/bid/51169
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71969
- https://github.com/bsdperimeter/pfsense/commit/1379d66f11aaf72982a70287b83e24efc
- https://github.com/bsdperimeter/pfsense/commit/87b4deb2b2dae9013e6aa0fe490d6a5a0
FAQ
What is CVE-2011-4197?
CVE-2011-4197 is a vulnerability with a CVSS score of 7.5 (HIGH). etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificat...
How severe is CVE-2011-4197?
CVE-2011-4197 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-4197?
Check the references section above for vendor advisories and patch information. Affected products include: Pfsense Pfsense.