← Back

CVE-2022-2393

nvd nist
Published: Jul 14, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD

Description

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.

Affected (7)

Pki Core
2 products
Certificate System
Enterprise Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 10.12.4
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 10.0
Version 9.0
Redhat
Version 6.0
Version 7.0
Version 8.0
Version 9.0

References (2)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.