← Vulnerability feed

Vulnerability record · CVE-2008-5082 · published 30 January 2009

CVE-2008-5082: Redhat dogtag certificate system improper authentication vulnerability

Redhat · Dogtag Certificate System

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass intended authentication policies by performing enrollment with a software key.

6.0 CVSS 2.0 Medium EPSS 0.78% · top 45.9% CWE-287 · Improper authentication
6.0CVSS 2.0 base score
0.78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass intended authentication policies by performing enrollment with a software key.

AV:N/AC:M/Au:S/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5082 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2021-20179Dogtagpki incorrect authorization vulnerabilityA flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …EPSS 1.2%7.5CVE-2013-1886Redhat certificate system vulnerabilityFormat string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System …EPSS 2.2%6.5CVE-2017-7509Redhat certificate system improper input validation vulnerabilityAn input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…EPSS 0.73%6.5CVE-2009-0588Redhat certificate system vulnerabilityagent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remot…EPSS 1.3%5.8CVE-2010-3868Redhat certificate system improper authentication vulnerabilityRed Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, w…EPSS 1.3%5.7CVE-2022-2393Pki-core project pki-core improper authorization vulnerabilityA flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.…EPSS 0.25%5.5CVE-2012-3367Redhat certificate system vulnerabilityRed Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the…EPSS 1.2%5.4CVE-2020-1696Redhat certificate system cross-site scripting vulnerabilityA flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a…EPSS 0.76%

Source: NIST National Vulnerability Database (record CVE-2008-5082), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.