V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2012-5484
CVE
Medium

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which…

CVSS
6.8
Medium
EPSS
0.01
p41
Published
2012-01-01
Updated
2012-01-01
Description

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

Tags · CWE
CWE-310
Affected products
Freeipa
CVSS vector
AV:A/AC:H/Au:N/C:C/I:C/A:C
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: A
Adjacent Network (A)
Attack Complexity
AC: H
High (H)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.006 · p41
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
freeipaTracked
freeipaTracked
freeipaTracked
freeipaTracked
freeipaTracked
freeipaTracked
freeipaTracked
ipaTracked
ipa-clientTracked
freeipa*Tracked
freeipa*Tracked