CVE-2010-4021 describes a vulnerability in the Key Distribution Center (KDC) of MIT Kerberos 5 (krb5) version 1.7. This flaw allows remote authenticated users to potentially impersonate a client by manipulating TGS requests, specifically by rewriting an inner request, a weakness known as a "KrbFastReq forgery issue." The vulnerability has a CVSS score of 2.1, indicating a low severity with network access, high attack complexity, authenticated user requirement, and a potential impact of partial integrity compromise. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:S/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.