PT-2023-25335 · Ysoft · Ysoft Safeq 6 Server
CVE-2023-35833
·
Publicado
2023-07-13
·
Atualizado
2024-08-02
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
YSoft SAFEQ 6 Server versions prior to 6.0.82
Description
An issue was discovered in YSoft SAFEQ 6 Server where modifying the URL of the LDAP server configuration from LDAPS to LDAP does not require the password to be reentered. This results in exposing cleartext credentials when connecting to a rogue LDAP server.
Recommendations
For versions prior to 6.0.82, update to version 6.0.82 or later to resolve the issue. As a temporary workaround, consider restricting access to the LDAP server configuration to minimize the risk of exploitation. Avoid using the LDAP configuration without proper authentication until the issue is resolved.
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ysoft Safeq 6 Server