Certificate System
Vendor:
First CVE: Jul 7, 2008 · Active for 18 years
19
Total CVEs
More Total CVEs than 93% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Certificate System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2008
18 years ago
Most Recent CVE
Jul 14, 2022
1,472 days ago
CVE Severity & Scoring
Certificate System19 CVEs
11%
74%
16%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (21.1%)
Unknown14 (73.7%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low5 (26.3%)
High0 (0.0%)
Unknown14 (73.7%)
User Interaction
None3 (15.8%)
Unknown14 (73.7%)
Required2 (10.5%)
Privileges Required
Low4 (21.1%)
High1 (5.3%)
None0 (0.0%)
Unknown14 (73.7%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20179HIGH A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is no | Mar 15, 2021 | 8.1 | 26 | NO | NO |
CVE-2017-7509MEDIUM An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is not present in a certificate a | Jul 26, 2018 | 6.5 | 22 | NO | NO |
CVE-2008-1676HIGH Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not | Jul 7, 2008 | 7.5 | 21 | NO | NO |
CVE-2022-2393MEDIUM A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authentica | Jul 14, 2022 | 5.7 | 20 | NO | NO |
CVE-2013-1886HIGH Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenti | Jan 24, 2014 | 7.5 | 20 | NO | NO |
CVE-2010-3868MEDIUM Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to | Nov 17, 2010 | 5.8 | 20 | NO | NO |
CVE-2019-10180MEDIUM A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resu | Mar 31, 2020 | 4.8 | 19 | NO | NO |
CVE-2020-1696MEDIUM A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (X | Mar 20, 2020 | 5.4 | 19 | NO | NO |
CVE-2012-3367MEDIUM Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows re | Aug 13, 2012 | 5.5 | 19 | NO | NO |
CVE-2009-0588MEDIUM agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approv | May 27, 2009 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Certificate System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0 | 2 | 5.5 | 0.5% | 0 | 0 |
| 8.1 | 5 | 4.8 | 1.4% | 0 | 0 |
| 8.0 | 5 | 4.4 | 1.2% | 0 | 0 |
| 8 | 6 | 4.7 | 1.2% | 0 | 0 |
| 7.3 | 9 | 4.9 | 1.1% | 0 | 0 |
| 7.2 | 8 | 4.0 | 0.9% | 0 | 0 |
| 7.1 | 6 | 4.7 | 1.1% | 0 | 0 |
| 10.0 | 4 | 6.0 | 0.7% | 0 | 0 |