CVE-2008-3280
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs (currently an untracked issue), this means that it is impossible to rely on these OPs.
- Affected products
- Openid
- Openid
- All versions
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 4.0% (89th percentile)
- Weakness
- CWE-338
- NVD status
- Modified
- Published
- 2021-05-21
CVE-2008-3280 at NVD
1 known exploit for CVE-2008-3280
Proof-of-concept code and exploit modules indexed by Sploitus