Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2393


A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.


Published

2022-07-14T15:15:08.133

Last Modified

2024-11-21T07:00:54.100

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-285
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pki-core_project pki-core ≤ 10.12.4 Yes
Application redhat certificate_system 9.0 Yes
Application redhat certificate_system 10.0 Yes
Operating System redhat enterprise_linux 6.0 Yes
Operating System redhat enterprise_linux 7.0 Yes
Operating System redhat enterprise_linux 8.0 Yes
Operating System redhat enterprise_linux 9.0 Yes

References