CVE-2025-3576
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.34%
- CWE
- CWE-328
- Published
- 2025-04-15
- Last modified
- 2026-09-01
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service
- Red Hat Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Weakness type
Related vulnerabilities
- CVE-2025-41652 — Weidmueller: Authentication Bypass Vulnerability in Industrial Ethernet Switches
- CVE-2025-27595 — Weak hashing alghrythm
- CVE-2023-0452 — Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configura
- CVE-2024-54143 — openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injection
- CVE-2023-46133 — crypto-es PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
- CVE-2024-48847 — MD5 bypass operation
- CVE-2023-43635 — Vault Key Sealed With SHA1 PCRs
- CVE-2023-43630 — Config Partition Not Measured From 2 Fronts