PT-2001-2537 · Mit · Kerberos

Publicado

2001-08-27

·

Atualizado

2017-07-11

·

CVE-2001-1444

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Kerberos versions (affected versions not specified)
Description The issue concerns the Kerberos Telnet protocol, which does not properly encrypt authentication and encryption options sent from the server. This allows remote attackers to perform a man-in-the-middle attack and potentially downgrade the authentication and encryption mechanisms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1444

Produtos afetados

Kerberos