GHSA-rfh5-gx7w-h7v7 · Severity: medium — A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4...
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
Conclusion & alert: CVE-2025-3576 is rated Moderate Risk (40.9/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.26%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-24 | 0.23% | 0.26% | +0.03% |
| 2 | 2026-02-20 | 0.26% | 0.23% | -0.03% |
| 3 | 2026-02-09 | — | 0.26% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
GHSA-rfh5-gx7w-h7v7 · Severity: medium — A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-3576 not yet assigned priority: Debian including 1 source packages (krb5), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-3576 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-3576 |
suse
|
medium | CVE-2025-3576 severity moderate: SUSE including 357 source package names (0.0.17-1.1:krb5-1.20.1-150600.11.14.1, 0.1.6-2.11:krb5-1.20.1-150600.11.14.1, …), 937 product×package rows across 362 product lines (Container bci/kiwi, Container bci/spack, … (362 product lines)): Fixed 687, Known Affected 226, Known Not Affected 24. | https://www.suse.com/security/cve/CVE-2025-3576/ |
ubuntu
|
medium | CVE-2025-3576 medium priority: Ubuntu including 1 source packages (krb5), 10 status rows across 10 suites (bionic, focal, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): released 7, not-affected 3. | https://ubuntu.com/security/CVE-2025-3576 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||