CVE-1999-0143
CVSS 2.0 Score 4.6 of 10 (medium)
Details
Summary
CVE-1999-0143 is a vulnerability affecting Kerberos 4 key servers. This issue allows an unauthenticated attacker to break and generate session keys, enabling them to masquerade as another user. The vulnerability arises from weak encryption algorithms used by these key servers, making it possible for an attacker to decrypt and modify the tickets used for authentication. As a result, the attacked user's identity can be impersonated, potentially leading to unauthorized access to sensitive information or systems. This vulnerability is significant due to the widespread use of the Kerberos 4 protocol during the late 1990s and early 2000s, making it crucial for organizations to address this issue promptly through patches or upgrades to a more secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- MIT Kerberos
- SunOS
Affected Vendors
- Oracle Corp
- Massachusetts Institute of Technology