PT-2007-5754 · Entrust · Entrust Entelligence Security Provider

Publicado

2007-08-29

·

Atualizado

2017-07-29

·

CVE-2007-4594

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Entrust Entelligence Security Provider (ESP) version 8
Description The issue arises from improper certificate validation under specific circumstances, including when the certificate chain omits the root Certification Authority (CA) certificate, or when an application is set to disregard unknown revocation statuses or certain certification path errors. This could potentially allow attackers to spoof certificate authentication in context-dependent scenarios.
Recommendations For Entrust Entelligence Security Provider (ESP) version 8, ensure proper certificate validation by verifying the complete certificate chain, including the root CA certificate, and configure applications to check revocation statuses and validate certification paths thoroughly. As a temporary workaround, consider enhancing certificate validation checks to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4594

Produtos afetados

Entrust Entelligence Security Provider