Lucene search

K
nvd[email protected]NVD:CVE-2014-5351
HistoryOct 10, 2014 - 1:55 a.m.

CVE-2014-5351

2014-10-1001:55:11
CWE-255
web.nvd.nist.gov
7

CVSS2

2.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.003

Percentile

68.1%

The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold request, which allows remote authenticated users to forge tickets by leveraging administrative access.

Affected configurations

Nvd
Node
mitkerberos_5Match1.12.2
VendorProductVersionCPE
mitkerberos_51.12.2cpe:2.3:a:mit:kerberos_5:1.12.2:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.003

Percentile

68.1%