CVE-1999-0143

CVSS 2.0 Score 4.6 of 10 (medium)

Details

Published Feb 21, 1996
Updated: Nov 20, 2024

Summary

CVE-1999-0143 is a vulnerability affecting Kerberos 4 key servers. This issue allows an unauthenticated attacker to break and generate session keys, enabling them to masquerade as another user. The vulnerability arises from weak encryption algorithms used by these key servers, making it possible for an attacker to decrypt and modify the tickets used for authentication. As a result, the attacked user's identity can be impersonated, potentially leading to unauthorized access to sensitive information or systems. This vulnerability is significant due to the widespread use of the Kerberos 4 protocol during the late 1990s and early 2000s, making it crucial for organizations to address this issue promptly through patches or upgrades to a more secure version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • MIT Kerberos
  • SunOS

Affected Vendors

  • Oracle Corp
  • Massachusetts Institute of Technology