CVE-2015-3206 — Improper Authentication in Kerberos
CWE-287 — Improper AuthenticationCWE-304 — Missing Critical Step in Authentication10 documents7 sources
Severity
8.1HIGHNVD
EPSS
0.6%
top 30.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 25
Latest updateMay 14
Description
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9
Affected Packages1 packages
Patches
🔴Vulnerability Details
4CVEList▶
CVE-2015-3206: The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a↗2017-08-25
OSV▶
CVE-2015-3206: The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a↗2017-08-25
📋Vendor Advisories
2💬Community
3Bugzilla
▶
Bugzilla▶
CVE-2015-3206 python-kerberos: checkPassword() does not verify KDC authenticity [fedora-all]↗2015-05-21