V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2010-1324
DEB
LowConfirmedExploit available

MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remot…

CVSS
3.7
Low
EPSS
0.03
p87
Published
2010-01-01
Updated
2010-01-01
Description

MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key.

Tags · CWE
Pre-auth
CWE-310
Affected products
Kerberos_5
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Timeline
2010-01-01
Published
2010-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.035 · p87
Known exploited (KEV)
No
Known exploits — Сканер-ВС
33855
exploitdb · https://www.exploit-db.com/exploits/33855
Enterprise
35606
exploitdb · https://www.exploit-db.com/exploits/35606
Enterprise
Affected software
ProductVendorStatus
krb5Tracked
krb5Tracked
krb5Tracked
krb5Tracked
kerberos_5*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities