Vulnerabilities
Vulnerable Software
Redhat:  >> Freeipa  >> 3.0.2  Security Vulnerabilities
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request without a username/dn, related to the 389 directory server.
CVSS Score
5.0
EPSS Score
0.013
Published
2014-11-03
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.
CVSS Score
5.0
EPSS Score
0.004
Published
2014-05-29
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
CVSS Score
7.9
EPSS Score
0.005
Published
2013-01-27


Contact Us

Shodan ® - All rights reserved