The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Metrics
Affected Vendors & Products
References
History
Tue, 10 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 26 Nov 2024 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. | |
Weaknesses | CWE-767 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-12-10T15:43:40.628Z
Reserved: 2024-05-22T09:00:13.769Z
Link: CVE-2024-34162

Updated: 2024-12-10T15:43:37.027Z

Status : Received
Published: 2024-11-26T08:15:06.123
Modified: 2024-11-26T08:15:06.123
Link: CVE-2024-34162

No data.