CVE-2015-3206Improper Authentication in Kerberos

Severity
8.1HIGHNVD
EPSS
0.6%
top 30.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 25
Latest updateMay 14

Description

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages1 packages

PyPImit/kerberos1.2.5

Patches

🔴Vulnerability Details

4
OSV
python-kerberos vulnerable to KDC spoofing attacks2022-05-14
GHSA
python-kerberos vulnerable to KDC spoofing attacks2022-05-14
CVEList
CVE-2015-3206: The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a2017-08-25
OSV
CVE-2015-3206: The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a2017-08-25

📋Vendor Advisories

2
Red Hat
python-kerberos: checkPassword() does not verify KDC authenticity2015-05-21
Debian
CVE-2015-3206: pykerberos - The checkPassword function in python-kerberos does not authenticate the KDC it a...2015

💬Community

3
Bugzilla
CVE-2015-3206 python-kerberos: checkPassword() does not verify KDC authenticity2015-05-21
Bugzilla
CVE-2015-3206 python-kerberos: checkPassword() does not verify KDC authenticity [epel-5]2015-05-21
Bugzilla
CVE-2015-3206 python-kerberos: checkPassword() does not verify KDC authenticity [fedora-all]2015-05-21
CVE-2015-3206 — Improper Authentication in MIT Kerberos | cvebase