PT-2018-8402 · Red Hat+2 · Pki-Core+3

Adam Mariš

·

Published

2017-08-01

·

Updated

2024-12-10

·

CVE-2017-7537

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions pki-core versions prior to 10.6.4
Description A flaw was discovered in the pki-core package where a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default. This could allow an attacker to bypass the regular authentication process and trick the CA server into issuing certificates.
Recommendations For versions prior to 10.6.4, update to version 10.6.4 or later to resolve the issue. As a temporary workaround, consider disabling the mock CMC authentication plugin until a patch is available.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2017-7537
ELSA-2017-2335
RHSA-2017:2335
RHSA-2017_2335
USN-7146-1

Affected Products

Linuxmint
Red Hat
Ubuntu
Pki-Core