CVE-2017-6594 describes a vulnerability in Heimdal (versions prior to 7.3) and related products like OpenSUSE, where attackers could bypass transit path validation by manipulating ticket issuance to omit the previous hop realm. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and could lead to high integrity impact, though it does not affect confidentiality or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.2.0CPE matchmatch criteria | cpe:2.3:a:heimdal_project:heimdal:*:*:*:*:*:*:*:* | ||
42.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:* | ||
42.3CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.