CVE-2017-2590 describes a privilege escalation vulnerability in FreeIPA versions prior to 4.4. Specifically, the IdM ca-del, ca-disable, and ca-enable commands failed to properly validate user permissions when interacting with Dogtag CAs. This flaw allows an authenticated but unauthorized attacker to delete, disable, or enable Certificate Authorities. The vulnerability carries a CVSS v3 score of 8.1 (High), indicating a significant risk. An attacker can exploit this remotely with low privileges and no user interaction, leading to high impact on both integrity and availability. This could result in denial of service for certificate issuance, OCSP signing, and the deletion of secret keys. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.4.0CPE matchmatch criteria | cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.