Kerberos Client Vulnerability in Fedora's KDC
CVE-2019-14844

7.5HIGH

Key Information:

Vendor

Mit

Status
Vendor
CVE Published:
26 September 2019

What is CVE-2019-14844?

A flaw exists in the Fedora versions of krb5 (ranging from 1.16.1 up to 1.17.x), whereby a remote unauthenticated user could exploit this vulnerability by sending specific enctype requests defined in RFC 4556. This could result in a crash of the Key Distribution Center (KDC), disrupting service for legitimate users and affecting the overall security infrastructure relying on Kerberos authentication.

Affected Version(s)

krb5 Fedora versions of krb5 from 1.16.1 to, including 1.17.x

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.