SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-35518

This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

MEDIUM 5.3EPSS 1.54%

Does this matter?

Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.

Description

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.54% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-203
Affected
redhat/389 directory server · redhat/directory server · redhat/enterprise linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.