#VU77582 Improper Authentication in FreeBSD - CVE-2023-3326
Published: June 21, 2023 / Updated: August 2, 2023
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in pam_krb5 module. A remote attacker with ability to control password and KDC responses can return a valid TGT ticket and bypass authentication process.
Successful exploitation of the vulnerability requires a non-default FreeBSD installation that leverages pam_krb5 for authentication and does not have a keytab provisioned.