PT-2007-5754 · Entrust · Entrust Entelligence Security Provider

Published

2007-08-29

·

Updated

2017-07-29

·

CVE-2007-4594

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Entrust Entelligence Security Provider (ESP) version 8
Description The issue arises from improper certificate validation under specific circumstances, including when the certificate chain omits the root Certification Authority (CA) certificate, or when an application is set to disregard unknown revocation statuses or certain certification path errors. This could potentially allow attackers to spoof certificate authentication in context-dependent scenarios.
Recommendations For Entrust Entelligence Security Provider (ESP) version 8, ensure proper certificate validation by verifying the complete certificate chain, including the root CA certificate, and configure applications to check revocation statuses and validate certification paths thoroughly. As a temporary workaround, consider enhancing certificate validation checks to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4594

Affected Products

Entrust Entelligence Security Provider