VulnerabilityModified
CVE-2021-3825
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API.
CRITICAL 9.6EPSS 1.62%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
- CVSS 3.1
- 9.6 CRITICALCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 1.62% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- pardus/liderahenk
- Source
- iletisim@usom.gov.tr
References
- https://pentest.blog/liderahenk-0day-all-your-pardus-clients-belongs-to-me/Exploit, Third Party Advisory
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-21-0795
- https://www.usom.gov.tr/bildirim/tr-21-0795Third Party Advisory
- https://pentest.blog/liderahenk-0day-all-your-pardus-clients-belongs-to-me/Exploit, Third Party Advisory
- https://www.usom.gov.tr/bildirim/tr-21-0795Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.