03-02-26, 11:20 AM
[img]
[/img]
Issue Identified: Directory listing is enabled at the root level with no authentication required. Exposed folders include:
These directories contain Certificate Revocation Lists (CRLs), Authority Revocation Lists (ARLs), root and intermediate certificates, and certification policies related to:
[/img]Issue Identified: Directory listing is enabled at the root level with no authentication required. Exposed folders include:
- _arls/
- _cl@ve/
- _cnp/
- _csca/
- _cvca/
- _dnie/
These directories contain Certificate Revocation Lists (CRLs), Authority Revocation Lists (ARLs), root and intermediate certificates, and certification policies related to:
- Electronic DNI (DNIe)
- Cl@ve digital identity system
- Biometric passports
- Detailed reconnaissance of the PKI trust chain (enables targeted OSINT attacks).
- Download of current revocation lists → analysis of revoked certificates (potential for targeted exploitation).
- Facilitates chaining attacks if additional vulnerabilities (e.g., IDOR or path traversal) are present.

![[Image: 21796-policia-nacional-espana-400px.jpg]](https://i.ibb.co/mrLvFkGj/21796-policia-nacional-espana-400px.jpg)