Description
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Published: 2019-05-15
Score: 7.4 High
EPSS: 2.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-4455-1 heimdal security update
EUVD EUVD EUVD-2019-3750 In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Ubuntu USN Ubuntu USN USN-5675-1 Heimdal vulnerabilities
History

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Heimdal Project Heimdal
Opensuse Backports Sle Leap
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-15T20:49:22.320Z

Reserved: 2019-05-14T00:00:00.000Z

Link: CVE-2019-12098

cve-icon Vulnrichment

Updated: 2024-08-04T23:10:30.560Z

cve-icon NVD

Status : Modified

Published: 2019-05-15T23:29:00.277

Modified: 2026-04-15T21:17:00.653

Link: CVE-2019-12098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses