CVE-2017-7562
MEDIUMKrb5 <1.16.1 - Auth Bypass
Title source: llmDescription
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.
References (7)
Scores
CVSS v3
6.5
EPSS
0.0043
EPSS Percentile
62.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-295
CWE-287
Status
published
Affected Products (5)
redhat/enterprise_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation
mit/kerberos_5
< 1.16.1
Timeline
Published
Jul 26, 2018
Tracked Since
Feb 18, 2026