MEDIUM
login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password
Published Oct 23, 2007
6.8
MEDIUMCVSS 2.0
EPSS 1.11%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.