Multiple Vendor Simple Certificate Enrollment Protocol Authentication Security Bypass Vulnerability
BID:54216
Info
Multiple Vendor Simple Certificate Enrollment Protocol Authentication Security Bypass Vulnerability
| Bugtraq ID: | 54216 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2012 12:00AM |
| Updated: | Jun 27 2012 12:00AM |
| Credit: | Ted Shorter of Certified Security Solutions |
| Vulnerable: |
Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4 |
| Not Vulnerable: | |
Discussion
Multiple Vendor Simple Certificate Enrollment Protocol Authentication Security Bypass Vulnerability
Simple Certificate Enrollment Protocol implemented by multiple vendors is prone to a security-bypass vulnerability.
An attacker can exploit this issue to elevate their privileges by requesting a certificate of a higher privileged user.
Successfully exploiting this issue, an attacker can bypass certain security restrictions and gain unauthorized access.
Simple Certificate Enrollment Protocol implemented by multiple vendors is prone to a security-bypass vulnerability.
An attacker can exploit this issue to elevate their privileges by requesting a certificate of a higher privileged user.
Successfully exploiting this issue, an attacker can bypass certain security restrictions and gain unauthorized access.
Exploit / POC
Multiple Vendor Simple Certificate Enrollment Protocol Authentication Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Vendor Simple Certificate Enrollment Protocol Authentication Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Multiple Vendor Simple Certificate Enrollment Protocol Authentication Security Bypass Vulnerability
References:
References: