CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
58.1%
pam_krb5 authenticates a user by essentially running kinit with the
password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key
Distribution Center) over the network, as a way to verify the password.
However, if a keytab is not provisioned on the system, pam_krb5 has no way
to validate the response from the KDC, and essentially trusts the tgt
provided over the network as being valid. In a non-default FreeBSD
installation that leverages pam_krb5 for authentication and does not have a
keytab provisioned, an attacker that is able to control both the password
and the KDC responses can return a valid tgt, allowing authentication to
occur for any user on the system.
Author | Note |
---|---|
mdeslaur | per the comments on the oss-sec post, “pam_krb5 and sssd-krb5 are both affected by the same attack, but they have always been documented to be affected”. See the “verify_ap_req_nofail” option in the man page. Deferring this CVE to see if a fix will be available, or if this isn’t something that will ever get a fix because it works as documented. See https://www.openwall.com/lists/oss-security/2023/06/22/2 |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | libpam-krb5 | < any | UNKNOWN |
ubuntu | 20.04 | noarch | libpam-krb5 | < any | UNKNOWN |
ubuntu | 22.04 | noarch | libpam-krb5 | < any | UNKNOWN |
ubuntu | 24.04 | noarch | libpam-krb5 | < any | UNKNOWN |
ubuntu | 14.04 | noarch | libpam-krb5 | < any | UNKNOWN |
ubuntu | 16.04 | noarch | libpam-krb5 | < any | UNKNOWN |
ubuntu | 18.04 | noarch | sssd | < any | UNKNOWN |
ubuntu | 20.04 | noarch | sssd | < any | UNKNOWN |
ubuntu | 22.04 | noarch | sssd | < any | UNKNOWN |
ubuntu | 24.04 | noarch | sssd | < any | UNKNOWN |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
58.1%