Authentication Bypass Vulnerability in krb5's Certauth Interface Affecting Red Hat
CVE-2017-7562

6.5MEDIUM

Key Information:

Vendor

Mit

Status
Vendor
CVE Published:
26 July 2018

What is CVE-2017-7562?

An authentication bypass flaw exists within the krb5's certauth interface before version 1.16.1, allowing remote attackers to potentially impersonate legitimate users by exploiting improperly handled client certificate validation. This situation arises under rare and erroneous conditions when an attacker can interact with the Key Distribution Center (KDC).

Affected Version(s)

krb5 1.16.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.