ipa: weakness when initiating join from IPA client can potentially compromise IPA domain
Published Jan 27, 2013
7.9
HIGHCVSS 2.0
EPSS 0.61%
Description
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.
Affected products
No data.
Configuration 1
No data.
Red Hat Enterprise Linux 5
ipa-client-0:2.1.3-5.el5_9.2
Fixed · RHSA-2013:0189
Red Hat Enterprise Linux 6
ipa-0:2.2.0-17.el6_3.1
Fixed · RHSA-2013:0188
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | ipa-client-0:2.1.3-5.el5_9.2 | Fixed | RHSA-2013:0189 |
| Red Hat Enterprise Linux 6 | ipa-0:2.2.0-17.el6_3.1 | Fixed | RHSA-2013:0188 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:A/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.61% (0.00611) | 47.35th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.56% (0.00557) | 41.81th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.58% (0.00583) | 67.11th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.08% (0.00078) | 35.74th | v3 (v2023.03.01) |
| Jun 26, 2024 | 0.08% (0.00078) | 34.04th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.08% (0.00078) | 32.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.54% (0.01537) | 74.00th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.69% (0.02686) | 82.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.54% (0.01537) | 51.33th | v2 (v2022.01.01) |
References (13)
- http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=18eea90ebb24a9c22248f0b7e18646cc6e3e3e0f x_refsource_CONFIRM
- http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=31e41eea6c2322689826e6065ceba82551c565aa x_refsource_CONFIRM
- http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=91f4af7e6af53e1c6bf17ed36cb2161863eddae4 x_refsource_CONFIRM
- http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a1991aeac19c3fec1fdd0d184c6760c90c9f9fc9 x_refsource_CONFIRM
- http://git.fedorahosted.org/cgit/freeipa.git/commit/?id=a40285c5a0288669b72f9d991508d4405885bffc x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHSA-2013-0188.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-0189.html vendor-advisoryx_refsource_REDHAT
- http://www.freeipa.org/page/CVE-2012-5484 x_refsource_CONFIRMVendor Advisory
- http://www.freeipa.org/page/Releases/3.1.2 x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2012-5484 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=876307 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2012-5484
- https://www.cve.org/CVERecord?id=CVE-2012-5484
Change history (0)
No recorded changes yet.