Kerberos Client Vulnerability in Fedora's KDC
CVE-2019-14844
7.5HIGH
What is CVE-2019-14844?
A flaw exists in the Fedora versions of krb5 (ranging from 1.16.1 up to 1.17.x), whereby a remote unauthenticated user could exploit this vulnerability by sending specific enctype requests defined in RFC 4556. This could result in a crash of the Key Distribution Center (KDC), disrupting service for legitimate users and affecting the overall security infrastructure relying on Kerberos authentication.
Affected Version(s)
krb5 Fedora versions of krb5 from 1.16.1 to, including 1.17.x
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
