{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-07T01:24:10.072","vulnerabilities":[{"cve":{"id":"CVE-2025-3576","sourceIdentifier":"secalert@redhat.com","published":"2025-04-15T06:15:44.047","lastModified":"2026-05-12T13:17:18.280","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering."},{"lang":"es","value":"Una vulnerabilidad en la implementación de MIT Kerberos permite la falsificación de mensajes protegidos por GSSAPI que utilizan RC4-HMAC-MD5 debido a debilidades en el diseño de la suma de comprobación MD5. Si se prefiere RC4 a tipos de cifrado más robustos, un atacante podría aprovechar las colisiones MD5 para falsificar códigos de integridad de mensajes. Esto podría provocar la manipulación no autorizada de mensajes."}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-328"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2025:11487","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:13664","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:13777","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15000","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15001","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15002","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15003","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15004","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:8411","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9418","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9430","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-3576","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2359465","source":"secalert@redhat.com"},{"url":"https://web.mit.edu/kerberos/krb5-1.22/krb5-1.22.html","source":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00047.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-577017.html","source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}]}}]}