9.6
CVE-2021-3825
- EPSS 1.57%
- Veröffentlicht 01.10.2021 15:15:07
- Zuletzt bearbeitet 18.05.2026 09:16:22
- Quelle iletisim@usom.gov.tr
- CVE-Watchlists
- Unerledigt
Missing Authorization Checks in LiderAhenk
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pardus ≫ Liderahenk Version <= 2.1.15
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.57% | 0.721 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| iletisim@usom.gov.tr | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://pentest.blog/liderahenk-0day-all-your-pardus-clients-belongs-to-me/
https://www.usom.gov.tr/bildirim/tr-21-0795
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-21-0795