CVE-2007-4594
Last modified
CVE-2007-4594 is a vulnerability of currently unknown severity. Entrust Entelligence Security Provider (ESP) 8 does not properly validate certificates in certain circumstances involving (1) a chain that omits the root Certification Authority (CA) certificate, or an application that specifies disregarding (2) unknown revocation statuses during path validation or (3) certain errors in the certification path, which might allow context-dependent attackers to spoof certificate authentication. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
Entrust Entelligence Security Provider (ESP) 8 does not properly validate certificates in certain circumstances involving (1) a chain that omits the root Certification Authority (CA) certificate, or an application that specifies disregarding (2) unknown revocation statuses during path validation or (3) certain errors in the certification path, which might allow context-dependent attackers to spoof certificate authentication. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Entrust | Entelligence Security Provider | 8 |
References
- http://secunia.com/advisories/26630Patch, Vendor Advisory
- http://secunia.com/advisories/26630Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4594?
How severe is CVE-2007-4594?
How do I fix CVE-2007-4594?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4588Multiple cross-site scripting (XSS) vulnerabilities in Inter…
- CVE-2007-4589Multiple cross-site scripting (XSS) vulnerabilities in Inter…
- CVE-2007-4590The get_system_info command in Ignite-UX C.7.0 through C.7.3…
- CVE-2007-4591vstor-ws60.sys in VMWare Workstation 6.0 allows local users …
- CVE-2007-4592Multiple cross-site scripting (XSS) vulnerabilities in the w…
- CVE-2007-4593Unspecified vulnerability in vstor2-ws60.sys in VMWare Works…
- CVE-2007-4595Cross-site scripting (XSS) vulnerability in Mayaa before 1.1…
- CVE-2007-4596The perl extension in PHP does not follow safe_mode restrict…
- CVE-2007-4597SQL injection vulnerability in index.php in TurnkeyWebTools …
- CVE-2007-4598IBM SurePOS 500 has (1) a default password of "12345" for th…
- CVE-2007-4599Stack-based buffer overflow in RealNetworks RealPlayer 10 an…
- CVE-2007-4600The "Protect Worksheet" functionality in Mathsoft Mathcad 12…
Are you affected by CVE-2007-4594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
