Vulnerability Details CVE-2003-0960
OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2003-0960
-
cpe:2.3:a:openca:openca:0.8.0
-
cpe:2.3:a:openca:openca:0.8.1
-
cpe:2.3:a:openca:openca:0.8.6
-
cpe:2.3:a:openca:openca:0.9.0
-
cpe:2.3:a:openca:openca:0.9.0.1
-
cpe:2.3:a:openca:openca:0.9.0.2
-
cpe:2.3:a:openca:openca:0.9.1
-
cpe:2.3:a:openca:openca:0.9.1.2
-
cpe:2.3:a:openca:openca:0.9.1.3