LOW · 3.7

CVE-2010-0014

System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary passw...

Vulnerability Description

System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user's Kerberos ticket-granting ticket (TGT); and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.

CVSS Score

3.7

LOW

AV:L/AC:H/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
FedoraprojectSssd<= 1.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-0014?

CVE-2010-0014 is a vulnerability with a CVSS score of 3.7 (LOW). System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary passw...

How severe is CVE-2010-0014?

CVE-2010-0014 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0014?

Check the references section above for vendor advisories and patch information. Affected products include: Fedoraproject Sssd.