« Volver al listado

CVE-2014-7828

Estado: ModificadaBaja (3.5)—

FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-7828",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-11-19T18:59:08.097",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-November/143000.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.freeipa.org/page/Releases/4.1.1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/70932",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1160871",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98500",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://fedorahosted.org/freeipa/ticket/4690",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://www.redhat.com/archives/freeipa-devel/2014-November/msg00068.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://www.redhat.com/archives/freeipa-users/2014-November/msg00077.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-November/143000.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.freeipa.org/page/Releases/4.1.1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/70932",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1160871",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98500",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://fedorahosted.org/freeipa/ticket/4690",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/freeipa-devel/2014-November/msg00068.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/freeipa-users/2014-November/msg00077.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind."
    },
    {
      "lang": "es",
      "value": "FreeIPA 4.0.x anterior a 4.0.5 y 4.1.x anterior a 4.1.1, cuando 2FA está activado, permite a atacantes remotos evadir la contraseña requerida por la autenticación de dos factores aprovechando un token OTP habilitado, lo que provoca un bind anónimo."
    }
  ],
  "lastModified": "2026-06-17T00:15:47.043",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:freeipa:freeipa:4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71429C12-3A4D-4412-9550-E791883A7E2C"
            },
            {
              "criteria": "cpe:2.3:a:freeipa:freeipa:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "865A81F2-D9BD-47DC-A635-EA3B122CB66A"
            },
            {
              "criteria": "cpe:2.3:a:freeipa:freeipa:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52E797DF-4F3A-464D-B49E-142292C95DF1"
            },
            {
              "criteria": "cpe:2.3:a:freeipa:freeipa:4.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4E97AAF-77F5-4BC4-8857-C3966EA117B0"
            },
            {
              "criteria": "cpe:2.3:a:freeipa:freeipa:4.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0115B8E-7AD4-41D7-A785-DB3441CEF886"
            },
            {
              "criteria": "cpe:2.3:a:freeipa:freeipa:4.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7BA432C-89F2-4207-B867-05B7C386F5A7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}