Security Advisory

CVE-2021-3551

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-02-16 16:37:57
Last updated 2024-08-03 17:01:06
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.