CVE-2007-4994
Estado: ModificadaAlta (7.5)—
Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the intended CRL.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.11%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-255
Referencias
- http://osvdb.org/40440
- http://secunia.com/advisories/27557
- http://www.redhat.com/support/errata/RHSA-2007-0934.html
- http://www.securityfocus.com/bid/26377
- http://www.securitytracker.com/id?1020532
- http://www.vupen.com/english/advisories/2007/3405
- http://www.vupen.com/english/advisories/2007/3406
- https://rhn.redhat.com/errata/RHSA-2008-0566.html
- http://osvdb.org/40440
- http://secunia.com/advisories/27557
- http://www.redhat.com/support/errata/RHSA-2007-0934.html
- http://www.securityfocus.com/bid/26377
- http://www.securitytracker.com/id?1020532
- http://www.vupen.com/english/advisories/2007/3405
- http://www.vupen.com/english/advisories/2007/3406
- https://rhn.redhat.com/errata/RHSA-2008-0566.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4994",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-11-06T21:46:00.000",
"references": [
{
"url": "http://osvdb.org/40440",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/27557",
"source": "secalert@redhat.com"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0934.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/26377",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id?1020532",
"source": "secalert@redhat.com"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3405",
"source": "secalert@redhat.com"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3406",
"source": "secalert@redhat.com"
},
{
"url": "https://rhn.redhat.com/errata/RHSA-2008-0566.html",
"source": "secalert@redhat.com"
},
{
"url": "http://osvdb.org/40440",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/27557",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0934.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/26377",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1020532",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3405",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3406",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://rhn.redhat.com/errata/RHSA-2008-0566.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the intended CRL."
},
{
"lang": "es",
"value": "Certificate Server 7.2 en Red Hat Certificate System (RHCS) no maneja de forma adecuada nuevas revocaciones que ocurren mientras un ertificate Revocation List (CRL) esté siendo generado, lo cual permite prevenir ciertas revocaciones de certificados desde la aparición del un CRL rapidamente y permitir a usuarios con certificados revocados evitar el CRL previsto."
}
],
"lastModified": "2026-06-16T22:45:14.587",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:certificate_server:7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "575AE74C-7079-49EE-BCFF-39406C4FD011"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}