V
Scaner-VSvulnerability catalog · v4.2
CVE-2010-4021
DEB
LowConfirmedExploit available

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS…

CVSS
2.1
Low
EPSS
0.00
p64
Published
2010-01-01
Updated
2010-01-01
Description

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, aka a "KrbFastReq forgery issue."

Tags · CWE
CWE-16
Affected products
Kerberos_5
CVSS vector
AV:N/AC:H/Au:S/C:N/I:P/A:N
Timeline
2010-01-01
Published
2010-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Authentication
Au: S
Single
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.005 · p64
Known exploited (KEV)
No
Known exploits — Сканер-ВС
33855
exploitdb · https://www.exploit-db.com/exploits/33855
Enterprise
35606
exploitdb · https://www.exploit-db.com/exploits/35606
Enterprise
Affected software
ProductVendorStatus
krb5Tracked
krb5Tracked
krb5Tracked
kerberos_5*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities