5
CVSSv2

CVE-2016-7030

Published: 28/08/2017 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote malicious users to cause a denial of service by locking out the account in which system services run on.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freeipa freeipa 4.6.0

Vendor Advisories

Synopsis Moderate: ipa security update Type/Severity Security Advisory: Moderate Topic An update for ipa is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which give ...
Debian Bug report logs - #849970 freeipa: CVE-2016-7030: DoS attack against kerberized services by abusing password policy Package: src:freeipa; Maintainer for src:freeipa is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 2 Jan 2017 19 ...
It was discovered that the default IdM password policies that lock out accounts after a certain number of failed login attempts were also applied to host and service accounts A remote unauthenticated user could use this flaw to cause a denial of service attack against kerberized services ...