Feed/CVE-2014-5351
CVE-2014-5351LOWCVSS 2.1

CVE-2014-5351

Published Oct 9, 2014·Updated Jun 16, 2026

NVD Description

The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold request, which allows remote authenticated users to forge tickets by leveraging administrative access.

CVSS Vector

AV:N/AC:H/Au:S/C:P/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free