|
Red Hat Certificate System contains a flaw related to the certificate authority's failure to prevent one-time PINs from being used more than once. The issue is triggered when a remote, authenticated attacker replays a single SCEP one-time PIN. This may allow an attacker to generate an arbitrary number of certificates.
|