CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.9 UNKNOWN
ADJACENT_NETWORK
MEDIUM
AV:A/AC:M/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
redhatfreeipa
2.0.0
redhatfreeipa
2.0.1
redhatfreeipa
2.1.0
redhatfreeipa
2.1.1
redhatfreeipa
2.1.3
redhatfreeipa
2.1.4
redhatfreeipa
2.2.1
redhatfreeipa
3.0.0
redhatfreeipa
3.0.1
redhatfreeipa
3.0.2
redhatfreeipa
3.1.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeipa
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
not-affected
raring
not-affected
quantal
ignored
precise
ignored
oneiric
dne
lucid
dne
hardy
dne
Common Weakness Enumeration