Improper Authentication in OpenLDAP - CVE-2011-1025

 

Improper Authentication in OpenLDAP - CVE-2011-1025

Published: March 20, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45195
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2011-1025
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: OpenLDAP.org
Affected software:
OpenLDAP

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.


How to mitigate CVE-2011-1025

Install update from vendor's website.

Sources