PT-2007-5754 · Entrust · Entrust Entelligence Security Provider
Publicado
2007-08-29
·
Atualizado
2017-07-29
·
CVE-2007-4594
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Entrust Entelligence Security Provider (ESP) version 8
Description
The issue arises from improper certificate validation under specific circumstances, including when the certificate chain omits the root Certification Authority (CA) certificate, or when an application is set to disregard unknown revocation statuses or certain certification path errors. This could potentially allow attackers to spoof certificate authentication in context-dependent scenarios.
Recommendations
For Entrust Entelligence Security Provider (ESP) version 8, ensure proper certificate validation by verifying the complete certificate chain, including the root CA certificate, and configure applications to check revocation statuses and validate certification paths thoroughly. As a temporary workaround, consider enhancing certificate validation checks to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Entrust Entelligence Security Provider