Lucene search

K
cve[email protected]CVE-2015-2694
HistoryMay 25, 2015 - 7:59 p.m.

CVE-2015-2694

2015-05-2519:59:02
CWE-264
web.nvd.nist.gov
93
cve-2015-2694
mit kerberos 5
krb5
kdcpreauth modules
preauthentication bypass

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

7.4

Confidence

High

EPSS

0.004

Percentile

74.6%

The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client’s request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.

Affected configurations

NVD
Node
mitkerberos_5Match1.12
OR
mitkerberos_5Match1.12.1
OR
mitkerberos_5Match1.12.2
OR
mitkerberos_5Match1.12.3
OR
mitkerberos_5Match1.13
OR
mitkerberos_5Match1.13.1
VendorProductVersionCPE
mitkerberos_51.12.1cpe:/a:mit:kerberos_5:1.12.1:::
mitkerberos_51.12.3cpe:/a:mit:kerberos_5:1.12.3:::
mitkerberos_51.12cpe:/a:mit:kerberos_5:1.12:::
mitkerberos_51.13.1cpe:/a:mit:kerberos_5:1.13.1:::
mitkerberos_51.13cpe:/a:mit:kerberos_5:1.13:::
mitkerberos_51.12.2cpe:/a:mit:kerberos_5:1.12.2:::

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

7.4

Confidence

High

EPSS

0.004

Percentile

74.6%