Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3206

Опубликовано: 25 авг. 2017
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apple:pykerberos:-:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00963
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

redhat
больше 10 лет назад

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

CVSS3: 8.1
debian
больше 8 лет назад

The checkPassword function in python-kerberos does not authenticate th ...

CVSS3: 8.1
github
больше 3 лет назад

python-kerberos vulnerable to KDC spoofing attacks

EPSS

Процентиль: 76%
0.00963
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-287