VulnerabilityModified
CVE-2013-4134
OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key.
MEDIUM 4.3EPSS 0.76%
Does this matter?
Lower severity and a low EPSS score (0.76%). Track it; it rarely justifies an emergency change on its own.
Description
OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- openafs/openafs · debian/debian linux
- Source
- secalert@redhat.com
References
- http://www.debian.org/security/2013/dsa-2729Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:244Broken Link
- http://www.openafs.org/pages/security/OPENAFS-SA-2013-003.txtVendor Advisory
- http://www.debian.org/security/2013/dsa-2729Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:244Broken Link
- http://www.openafs.org/pages/security/OPENAFS-SA-2013-003.txtVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.