First published: Mon Aug 27 2001(Updated: )
KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KTH Kerberos | =4 | |
KTH Kerberos | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1443 is considered a medium severity vulnerability due to the potential for man-in-the-middle attacks.
To fix CVE-2001-1443, ensure that both the client and server support and enforce encrypted communications during Telnet sessions.
CVE-2001-1443 affects users of KTH Kerberos IV and Kerberos V (Heimdal) Telnet clients.
CVE-2001-1443 allows remote attackers to conduct man-in-the-middle attacks by intercepting unencrypted communications.
CVE-2001-1443 was reported in the year 2001.