CVE-2024-34162CWE-767

The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users

Medium · published November 26, 2024

CVSS v3.1
5.3
EPSS
1%
Percentile
53.2
In the wild
Unconfirmed
What it is

The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00769 · 53.2th percentile
Weakness
CWE-767 · Access to Critical Private Variable via Public Method
Published
2024-11-26T07:37Z
EPSS history
Timeline
  • 26 NOV 07:37Z
    The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users
    cvelistv5