CVE-2016-9575
Estado: ModificadaMedia (6.3)—
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Puntuación base: 6.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.74%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
- CWE-285
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-9575",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "FreeIPA",
"product": "ipa",
"versions": [
{
"status": "affected",
"version": "4.2.x"
},
{
"status": "affected",
"version": "4.3.x before 4.3.3"
},
{
"status": "affected",
"version": "4.4.x before 4.4.3"
}
]
}
]
}
],
"published": "2018-03-13T13:29:00.217",
"references": [
{
"url": "http://rhn.redhat.com/errata/RHSA-2017-0001.html",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/95068",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1395311",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2017-0001.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/95068",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1395311",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-285"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks."
},
{
"lang": "es",
"value": "Ipa en versiones 4.2.x, 4.3.x anteriores a la 4.3.3 y 4.4.x anteriores a la 4.4.3 no comprobaba correctamente los permisos de usuario cuando se modificaban los perfiles de certificados en el comando certprofile-mod de IdM. Un atacante autenticado sin privilegios podría utilizar este fallo para modificar perfiles y enviar certificados con nombres arbitrarios o información de uso de claves y, como consecuencia, utilizar dichos certificados para otros ataques."
}
],
"lastModified": "2026-06-17T00:56:16.277",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D3E80C7-5169-4241-A0D2-44DDAB632390"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.2.0:alpha1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29F112C5-F09F-4852-BA25-ABC5E846D20E"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67B9782C-BDD1-4D54-9851-A92FB1AEC3BE"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F8BBE22-BBAC-42E8-97FD-5948CED7169A"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C012151-B96A-45E8-A915-D42511EECB88"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47014414-E33A-4F0E-A176-776D73F2B900"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "027670DD-56FD-4CC1-9C2C-0AB7876E8B1B"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B64FB1C5-B46C-4C9B-A9B3-19FA365C6957"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E5243F6-793F-4674-9460-6E47D8017F03"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "49C8B89B-CBD5-4917-8841-4D338F2726CD"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22800DB4-7B42-4CDF-98DF-28E3EC8A47AA"
},
{
"criteria": "cpe:2.3:a:freeipa:freeipa:4.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7FFECE21-6D83-4F86-9FDC-1CDA11346469"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}