Unrated severityNVD Advisory· Published Jan 3, 2012· Updated Apr 29, 2026
CVE-2011-4197
CVE-2011-4197
Description
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.
Affected products
5cpe:2.3:a:pfsense:pfsense:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:pfsense:pfsense:*:*:*:*:*:*:*:*range: <=2.0
- cpe:2.3:a:pfsense:pfsense:1.0.x:*:*:*:*:*:*:*
- cpe:2.3:a:pfsense:pfsense:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:pfsense:pfsense:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:pfsense:pfsense:1.2.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/46780nvdVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2011-12/0152.htmlnvd
- www.osvdb.org/77982nvd
- www.securityfocus.com/bid/51169nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/71969nvd
- github.com/bsdperimeter/pfsense/commit/1379d66f11aaf72982a70287b83e24efcd18898envd
- github.com/bsdperimeter/pfsense/commit/87b4deb2b2dae9013e6aa0fe490d6a5a04a27894nvd
- www.trustmatta.com/advisories/MATTA-2011-001.txtnvd
News mentions
0No linked articles in our index yet.