Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25

Количество 25

fstec логотип

BDU:2026-02738

12 месяцев назад

Уязвимость сервиса управления доступом к удаленным каталогам и механизма аутентификации SSSD, связанная с небезопасным управлением привилегиями, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260209-73-0015

8 месяцев назад

Уязвимость sssd

CVSS3: 8.8
EPSS: Низкий
altlinux логотип

ALT-PU-2026-5698

3 месяца назад

ALT-PU-2026-5698: package `sssd` update to version 2.9.8-alt3

CVSS3: 8.8
EPSS: Низкий
altlinux логотип

ALT-PU-2025-15236

10 месяцев назад

ALT-PU-2025-15236: package `sssd` update to version 2.9.7-alt1.p10.1

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2025-11561

12 месяцев назад

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-11561

12 месяцев назад

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-11561

12 месяцев назад

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-11561

12 месяцев назад

A flaw was found in the integration of Active Directory and the System ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20001-1

9 месяцев назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4247-1

10 месяцев назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4232-1

10 месяцев назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4231-1

10 месяцев назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4183-1

10 месяцев назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4182-1

10 месяцев назад

Security update for sssd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4181-1

10 месяцев назад

Security update for sssd

EPSS: Низкий
redos логотип

ROS-20260209-80-0021

8 месяцев назад

Уязвимость sssd

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2025:21020

10 месяцев назад

Important: sssd security update

EPSS: Низкий
rocky логотип

RLSA-2025:20954

10 месяцев назад

Important: sssd security update

EPSS: Низкий
rocky логотип

RLSA-2025:19610

11 месяцев назад

Important: sssd security update

EPSS: Низкий
github логотип

GHSA-gj84-8vfx-q3vm

12 месяцев назад

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, SSSD does not enable the Kerberos local authentication plugin (sssd_krb5_localauth_plugin), allowing an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users. This can result in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-02738

Уязвимость сервиса управления доступом к удаленным каталогам и механизма аутентификации SSSD, связанная с небезопасным управлением привилегиями, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 8.8
1%
Низкий
12 месяцев назад
redos логотип
ROS-20260209-73-0015

Уязвимость sssd

CVSS3: 8.8
1%
Низкий
8 месяцев назад
altlinux логотип
ALT-PU-2026-5698

ALT-PU-2026-5698: package `sssd` update to version 2.9.8-alt3

CVSS3: 8.8
1%
Низкий
3 месяца назад
altlinux логотип
ALT-PU-2025-15236

ALT-PU-2025-15236: package `sssd` update to version 2.9.7-alt1.p10.1

CVSS3: 8.8
1%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-11561

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
1%
Низкий
12 месяцев назад
redhat логотип
CVE-2025-11561

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
1%
Низкий
12 месяцев назад
nvd логотип
CVE-2025-11561

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users, potentially resulting in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
1%
Низкий
12 месяцев назад
debian логотип
CVE-2025-11561

A flaw was found in the integration of Active Directory and the System ...

CVSS3: 8.8
1%
Низкий
12 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20001-1

Security update for sssd

1%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4247-1

Security update for sssd

1%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4232-1

Security update for sssd

1%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4231-1

Security update for sssd

1%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4183-1

Security update for sssd

1%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4182-1

Security update for sssd

1%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4181-1

Security update for sssd

1%
Низкий
10 месяцев назад
redos логотип
ROS-20260209-80-0021

Уязвимость sssd

CVSS3: 8.8
1%
Низкий
8 месяцев назад
rocky логотип
RLSA-2025:21020

Important: sssd security update

1%
Низкий
10 месяцев назад
rocky логотип
RLSA-2025:20954

Important: sssd security update

1%
Низкий
10 месяцев назад
rocky логотип
RLSA-2025:19610

Important: sssd security update

1%
Низкий
11 месяцев назад
github логотип
GHSA-gj84-8vfx-q3vm

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, SSSD does not enable the Kerberos local authentication plugin (sssd_krb5_localauth_plugin), allowing an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users. This can result in unauthorized access or privilege escalation on domain-joined Linux hosts.

CVSS3: 8.8
1%
Низкий
12 месяцев назад

Уязвимостей на страницу