PT-2001-2537 · Mit · Kerberos

Published

2001-08-27

·

Updated

2017-07-11

·

CVE-2001-1444

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Kerberos versions (affected versions not specified)
Description The issue concerns the Kerberos Telnet protocol, which does not properly encrypt authentication and encryption options sent from the server. This allows remote attackers to perform a man-in-the-middle attack and potentially downgrade the authentication and encryption mechanisms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1444

Affected Products

Kerberos