Certificate System

Vendor:

First CVE: Jul 7, 2008 · Active for 18 years

19
Total CVEs
More Total CVEs than 93% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Certificate System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2008
18 years ago
Most Recent CVE
Jul 14, 2022
1,472 days ago

CVE Severity & Scoring

Certificate System19 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (21.1%)
Unknown14 (73.7%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low5 (26.3%)
High0 (0.0%)
Unknown14 (73.7%)
User Interaction
None3 (15.8%)
Unknown14 (73.7%)
Required2 (10.5%)
Privileges Required
Low4 (21.1%)
High1 (5.3%)
None0 (0.0%)
Unknown14 (73.7%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is no
Mar 15, 20218.126NONO
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is not present in a certificate a
Jul 26, 20186.522NONO
Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not
Jul 7, 20087.521NONO
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authentica
Jul 14, 20225.720NONO
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenti
Jan 24, 20147.520NONO
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to
Nov 17, 20105.820NONO
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resu
Mar 31, 20204.819NONO
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (X
Mar 20, 20205.419NONO
Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows re
Aug 13, 20125.519NONO
agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approv
May 27, 20096.518NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Certificate System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.025.50.5%00
8.154.81.4%00
8.054.41.2%00
864.71.2%00
7.394.91.1%00
7.284.00.9%00
7.164.71.1%00
10.046.00.7%00