CVE-2017-7562

MEDIUM

Krb5 <1.16.1 - Auth Bypass

Title source: llm

Description

An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.

Scores

CVSS v3 6.5
EPSS 0.0043
EPSS Percentile 62.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-295 CWE-287
Status published

Affected Products (5)

redhat/enterprise_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation
mit/kerberos_5 < 1.16.1

Timeline

Published Jul 26, 2018
Tracked Since Feb 18, 2026