SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9575

An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.

MEDIUM 6.3EPSS 0.74%

Does this matter?

Lower severity and a low EPSS score (0.74%). Track it; it rarely justifies an emergency change on its own.

Description

Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.

CVSS 3.0
6.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS
0.74% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-863, CWE-285
Affected
freeipa/freeipa
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.