CVE-2011-4083
Estado: ModificadaMedia (4.3)—
The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red Hat Network private entitlement keys and the (2) private key for the entitlement in an archive of debugging information, which might allow remote attackers to obtain sensitive information by reading the archive.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.00%
- Percentil entre todas las CVEs puntuadas: 62
- Fecha de la puntuación: 1/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-310
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-4083",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-02-17T16:55:07.273",
"references": [
{
"url": "http://rhn.redhat.com/errata/RHSA-2011-1536.html",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0153.html",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2011-1536.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0153.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red Hat Network private entitlement keys and the (2) private key for the entitlement in an archive of debugging information, which might allow remote attackers to obtain sensitive information by reading the archive."
},
{
"lang": "es",
"value": "La utilidad sosreport en el paquete sos de Red Hat anterior a 1.7-9 y 2.x anterior a 2.2-17 incluye (1) claves de derechos privadas basadas en certificado de Red Hat Network y la (2) clave privada para el derecho en un archivo con información de depuración, lo que podría permitir a atacantes remotos obtener información sensible mediante la lectura del archivo."
}
],
"lastModified": "2026-06-16T23:34:23.690",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22EEE016-AAA4-44D5-B82C-211E306D6A06"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B7125C6-7DB3-4447-B66D-2A863C7C758E"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72EC1F77-E9DF-4162-8F1A-28DBF21CC52B"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C0C2C21-5770-4D48-A1D8-D2DEBF1652F7"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B85DFD1-2903-43DF-B811-830E439EBA81"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FA0FF67-39A6-4E01-B092-55EFC9AEA446"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41B4DA50-0086-4253-8EFE-F290961BB7A4"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1ABC0B4D-E429-46BB-BA58-8A6AD3A3EF46"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67213CE4-E23B-4499-94DC-7CDFC6C5B4E4"
},
{
"criteria": "cpe:2.3:a:redhat:sos:2.2-16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E69CE230-0E4C-4BC7-BE83-F5AF3F97DE2B"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:sos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "861BFDE5-0104-4922-B542-B8DFE9E99EBB",
"versionEndIncluding": "1.7-6"
},
{
"criteria": "cpe:2.3:a:redhat:sos:1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB09510B-26F9-4B0B-872E-D114BD4645F2"
},
{
"criteria": "cpe:2.3:a:redhat:sos:1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5231190-05A6-4FDF-B298-585F86D15348"
},
{
"criteria": "cpe:2.3:a:redhat:sos:1.7-8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F3460E1-4C40-4405-9E04-9FAC0409E69F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}