// For flags

CVE-2013-0287

sssd: simple access provider flaw prevents intended ACL use when client to an AD provider

Severity Score

4.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

El Simple Access Provider en System Security Services Daemon (SSSD) v1.9.0 hasta v1.9.4, cuando usa el proveedor de Active Directory, no se aplica correctamente la opciĆ³n simple_deny_groups, lo que permite a usuarios remotos autenticados para eludir restricciones de acceso previstos.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-12-06 CVE Reserved
  • 2013-03-20 CVE Published
  • 2024-02-09 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (18)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Fedoraproject
Search vendor "Fedoraproject"
Sssd
Search vendor "Fedoraproject" for product "Sssd"
1.9.0
Search vendor "Fedoraproject" for product "Sssd" and version "1.9.0"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Sssd
Search vendor "Fedoraproject" for product "Sssd"
1.9.1
Search vendor "Fedoraproject" for product "Sssd" and version "1.9.1"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Sssd
Search vendor "Fedoraproject" for product "Sssd"
1.9.2
Search vendor "Fedoraproject" for product "Sssd" and version "1.9.2"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Sssd
Search vendor "Fedoraproject" for product "Sssd"
1.9.3
Search vendor "Fedoraproject" for product "Sssd" and version "1.9.3"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Sssd
Search vendor "Fedoraproject" for product "Sssd"
1.9.4
Search vendor "Fedoraproject" for product "Sssd" and version "1.9.4"
-
Affected