Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-9422

The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 allows remote authenticated users to bypass a kadmin/* authorization check and obtain administrative access by leveraging access to a two-component principal with an initial "kadmind" substring, as demonstrated by a "ka/x" principal.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 76.0%
CVSS Severity
CVSS v2 Score 6.1
References
Products affected by CVE-2014-9422
  • Mit » Kerberos 5 » Version: 1.11
    cpe:2.3:a:mit:kerberos_5:1.11
  • Mit » Kerberos 5 » Version: 1.11.1
    cpe:2.3:a:mit:kerberos_5:1.11.1
  • Mit » Kerberos 5 » Version: 1.11.2
    cpe:2.3:a:mit:kerberos_5:1.11.2
  • Mit » Kerberos 5 » Version: 1.11.3
    cpe:2.3:a:mit:kerberos_5:1.11.3
  • Mit » Kerberos 5 » Version: 1.11.4
    cpe:2.3:a:mit:kerberos_5:1.11.4
  • Mit » Kerberos 5 » Version: 1.11.5
    cpe:2.3:a:mit:kerberos_5:1.11.5
  • Mit » Kerberos 5 » Version: 1.12
    cpe:2.3:a:mit:kerberos_5:1.12
  • Mit » Kerberos 5 » Version: 1.12.1
    cpe:2.3:a:mit:kerberos_5:1.12.1
  • Mit » Kerberos 5 » Version: 1.12.2
    cpe:2.3:a:mit:kerberos_5:1.12.2
  • Mit » Kerberos 5 » Version: 1.13
    cpe:2.3:a:mit:kerberos_5:1.13


Contact Us

Shodan ® - All rights reserved