« Volver al listado

CVE-2012-3367

Estado: ModificadaMedia (5.5)—

Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-3367",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-13T20:55:08.397",
  "references": [
    {
      "url": "http://osvdb.org/84098",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-1103.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/50013",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/54608",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1027284",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=836268",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77102",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://fedorahosted.org/pki/changeset/2430",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://osvdb.org/84098",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-1103.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/50013",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/54608",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1027284",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=836268",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77102",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://fedorahosted.org/pki/changeset/2430",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate."
    },
    {
      "lang": "es",
      "value": "Red Hat Certificate System (RHCS) antes de v8.1.1 y Dogtag Certificate System no comprueban correctamente las solicitudes de revocación de certificados realizadas a través de la interfaz web, lo que permite revocar los certificados finales de entidad que revocan certificados de  autoridad de certificación (CA) a atacantes remotos con permisos.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:43:05.210",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:certificate_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE009B1B-E0AB-4BA4-9A18-5F2A45FDCB7F",
              "versionEndIncluding": "8.1"
            },
            {
              "criteria": "cpe:2.3:a:redhat:certificate_system:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A94B7103-11B7-4B1E-AE02-86210F9CCCAA"
            },
            {
              "criteria": "cpe:2.3:a:redhat:certificate_system:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27FE079E-FB15-443C-BE2E-1D4C940BB8C0"
            },
            {
              "criteria": "cpe:2.3:a:redhat:certificate_system:7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2654E6A-190C-4D5C-ABC0-89011DD8E293"
            },
            {
              "criteria": "cpe:2.3:a:redhat:certificate_system:8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2EF75FF-FCDB-433C-A7B9-4DBAABAC6643"
            },
            {
              "criteria": "cpe:2.3:a:redhat:certificate_system:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "969F1FDC-EB66-4758-B619-C48CA1E5B1AC"
            },
            {
              "criteria": "cpe:2.3:a:redhat:dogtag_certificate_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06D606EF-447B-42C5-ADBE-14515257262B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}