Security Advisory

CVE-2011-4197

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-01-03 19:00:00
Last updated 2024-08-07 00:01:51
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.