AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-12173

MEDIUM · CVSS 4.3 EPSS 1.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-12173
Severity
MEDIUM
CVSS
4.3
EPSS
1.50%

Original NVD Description

It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.