SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-2157

OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.

MEDIUM 4.3EPSS 3.13%

Does this matter?

Lower severity and a low EPSS score (3.13%). Track it; it rarely justifies an emergency change on its own.

Description

OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
3.13% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
openstack/keystone
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.