← Back to CVE List

CVE-2017-7537

Published: 2018-07-26T13:29Z
Last Modified: 2024-11-21T03:32Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing certificates. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt