CVE Vulnerabilities

CVE-2016-7030

Published: Aug 28, 2017 | Modified: Jan 05, 2018
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.

Affected Software

Name Vendor Start Version End Version
Freeipa Freeipa 4.6.0 (including) 4.6.0 (including)
Red Hat Enterprise Linux 7 RedHat ipa-0:4.4.0-14.el7_3.1.1 *
Freeipa Ubuntu artful *
Freeipa Ubuntu esm-apps/xenial *
Freeipa Ubuntu precise *
Freeipa Ubuntu trusty *
Freeipa Ubuntu trusty/esm *
Freeipa Ubuntu upstream *
Freeipa Ubuntu xenial *
Freeipa Ubuntu yakkety *
Freeipa Ubuntu zesty *

References