Unrated severityNVD Advisory· Published Jan 3, 2012· Updated Jun 16, 2026
CVE-2011-4197
CVE-2011-4197
Description
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:pfsense:pfsense:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:pfsense:pfsense:*:*:*:*:*:*:*:*range: <=2.0
- cpe:2.3:a:pfsense:pfsense:1.0.x:*:*:*:*:*:*:*
- cpe:2.3:a:pfsense:pfsense:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:pfsense:pfsense:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:pfsense:pfsense:1.2.3:*:*:*:*:*:*:*
- (no CPE)range: <2.0.1
Patches
Vulnerability mechanics
References
8- secunia.com/advisories/46780nvdVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2011-12/0152.htmlnvd
- www.osvdb.org/77982nvd
- www.securityfocus.com/bid/51169nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/71969nvd
- github.com/bsdperimeter/pfsense/commit/1379d66f11aaf72982a70287b83e24efcd18898envd
- github.com/bsdperimeter/pfsense/commit/87b4deb2b2dae9013e6aa0fe490d6a5a04a27894nvd
- www.trustmatta.com/advisories/MATTA-2011-001.txtnvd
News mentions
0No linked articles in our index yet.