7.9

CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

Data is provided by the National Vulnerability Database (NVD)
RedhatFreeipa Version2.0.0
RedhatFreeipa Version2.0.1
RedhatFreeipa Version2.1.0
RedhatFreeipa Version2.1.1
RedhatFreeipa Version2.1.3
RedhatFreeipa Version2.1.4
RedhatFreeipa Version2.2.1
RedhatFreeipa Version3.0.0
RedhatFreeipa Version3.0.1
RedhatFreeipa Version3.0.2
RedhatFreeipa Version3.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.646
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.9 5.5 10
AV:A/AC:M/Au:N/C:C/I:C/A:C