CVE-2020-28196
published 2020-11-06CVE-2020-28196: MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.37%
90.2th percentile
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | krb5 | < krb5 1.18.3-1 (bookworm) | krb5 1.18.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| mit | kerberos_5 | < 1.17.2 | 1.17.2 |
| mit | kerberos_5 | >= 1.18.0 < 1.18.3 | 1.18.3 |
| mit | krb5 | >= 0 < 1.18.3-1 | 1.18.3-1 |
| mit | krb5 | >= 0 < 1.18.3-1 | 1.18.3-1 |
| mit | krb5 | >= 0 < 1.18.3-1 | 1.18.3-1 |
| mit | krb5 | >= 0 < 1.18.3-1 | 1.18.3-1 |
| msrc | cm1_krb5_1.18.4-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | mysql_server | <= 8.0.23 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Oracle
Oracle Oracle Communications Risk Matrix: Policy (MIT Kerberos) — CVE-2020-28196
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2020-28196 [HIGH] Oracle Oracle Communications Risk Matrix: Policy (MIT Kerberos) — CVE-2020-28196
Oracle Oracle Communications Risk Matrix: Policy (MIT Kerberos) vulnerability
CVE: CVE-2020-28196
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: NM Core (Kerberos) — CVE-2020-28196
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2020-28196 [HIGH] Oracle Oracle Communications Applications Risk Matrix: NM Core (Kerberos) — CVE-2020-28196
Oracle Oracle Communications Applications Risk Matrix: NM Core (Kerberos) vulnerability
CVE: CVE-2020-28196
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Security: Encryption (MIT Kerberos) — CVE-2020-28196
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2020-28196 [HIGH] Oracle Oracle MySQL Risk Matrix: Server: Security: Encryption (MIT Kerberos) — CVE-2020-28196
Oracle Oracle MySQL Risk Matrix: Server: Security: Encryption (MIT Kerberos) vulnerability
CVE: CVE-2020-28196
CVSS: 7.5
Protocol: MySQL Protocol
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Ubuntu
Kerberos vulnerability
vendor_ubuntu·2020-11-17
CVE-2020-28196 Kerberos vulnerability
Title: Kerberos vulnerability
Summary: Kerberos could be made to consume unlimited resources if it received specially crafted
ASN.1.
Demi Obenour discovered that Kerberos incorrectly handled certain ASN.1.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite le
vendor_msrc·2020-11-10·CVSS 7.5
CVE-2020-28196 [HIGH] CWE-674 MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite le
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is
Red Hat
krb5: unbounded recursion via an ASN.1-encoded Kerberos message in lib/krb5/asn.1/asn1_encode.c may lead to DoS
vendor_redhat·2020-11-06·CVSS 7.5
CVE-2020-28196 [HIGH] CWE-674 krb5: unbounded recursion via an ASN.1-encoded Kerberos message in lib/krb5/asn.1/asn1_encode.c may lead to DoS
krb5: unbounded recursion via an ASN.1-encoded Kerberos message in lib/krb5/asn.1/asn1_encode.c may lead to DoS
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
A flaw was found in krb5. MIT Kerberos 5 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
Package: krb5 (Red Hat Enterprise Linux 5) - Not affected
Package: krb5 (Red Hat Enterprise Linux 6) - Not affected
Package: krb5 (Red Hat Enterprise Linux 7) - Out of support scope
Package: krb5 (Red Hat JBoss Core Services) - Not affected
Pa
Debian
CVE-2020-28196: krb5 - MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounde...
vendor_debian·2020·CVSS 7.5
CVE-2020-28196 [HIGH] CVE-2020-28196: krb5 - MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounde...
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
Scope: local
bookworm: resolved (fixed in 1.18.3-1)
bullseye: resolved (fixed in 1.18.3-1)
forky: resolved (fixed in 1.18.3-1)
sid: resolved (fixed in 1.18.3-1)
trixie: resolved (fixed in 1.18.3-1)
GHSA
GHSA-2wgw-3mv7-47xf: MIT Kerberos 5 (aka krb5) before 1
ghsa_unreviewed·2022-05-24
CVE-2020-28196 [HIGH] CWE-674 GHSA-2wgw-3mv7-47xf: MIT Kerberos 5 (aka krb5) before 1
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
OSV
CVE-2020-28196: MIT Kerberos 5 (aka krb5) before 1
osv·2020-11-06·CVSS 7.5
CVE-2020-28196 [HIGH] CVE-2020-28196: MIT Kerberos 5 (aka krb5) before 1
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
No detection rules found.
No public exploits indexed.
https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfdhttps://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/11/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/https://security.gentoo.org/glsa/202011-17https://security.netapp.com/advisory/ntap-20201202-0001/https://security.netapp.com/advisory/ntap-20210513-0002/https://www.debian.org/security/2020/dsa-4795https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfdhttps://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/11/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45KKOZQWIIIW5C45PJVGQ32AXBSYNBE7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/73IGOG6CZAVMVNS4GGRMOLOZ7B6QVA7F/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPH2V3WSQTELROZK3GFCPQDOFLKIZ6H5/https://security.gentoo.org/glsa/202011-17https://security.netapp.com/advisory/ntap-20201202-0001/https://security.netapp.com/advisory/ntap-20210513-0002/https://www.debian.org/security/2020/dsa-4795https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.html
2020-11-06
Published