Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7030

Опубликовано: 14 дек. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 4.3
EPSS Низкий

Описание

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.

It was discovered that the default IdM password policies that lock out accounts after a certain number of failed login attempts were also applied to host and service accounts. A remote unauthenticated user could use this flaw to cause a denial of service attack against kerberized services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ipaWill not fix
Red Hat Enterprise Linux 7ipaFixedRHSA-2017:000102.01.2017

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1370493ipa: DoS attack against kerberized services by abusing password policy

EPSS

Процентиль: 81%
0.0153
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.

CVSS3: 7.5
nvd
около 8 лет назад

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.

CVSS3: 7.5
debian
около 8 лет назад

FreeIPA uses a default password policy that locks an account after 5 u ...

CVSS3: 7.5
github
больше 3 лет назад

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.

oracle-oval
почти 9 лет назад

ELSA-2017-0001: ipa security update (MODERATE)

EPSS

Процентиль: 81%
0.0153
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2