Improper Authentication in OpenLDAP - CVE-2011-1025

 

Improper Authentication in OpenLDAP - CVE-2011-1025

Published: March 20, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45195
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1025
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.


Affected software

OpenLDAP

How to mitigate CVE-2011-1025

Install update from vendor's website.


External References

Related Security Bulletins