LDAP Authentication Sever Pass-back attack
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.7epss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Affected products
Xerox · Phaser 6510Xerox · Versalink B400Xerox · Versalink B405Xerox · Versalink B600/B610Xerox · Versalink B605/B615Xerox · Versalink B7025/B7030/B7035Xerox · Versalink B7125/B7130/B7135Xerox · Versalink C400Xerox · Versalink C405Xerox · Versalink C500/C600Xerox · Versalink C505/C605Xerox · Versalink C7000Xerox · Versalink C7020/C7025/C7030Xerox · Versalink C7120/C7125/C7130Xerox · Versalink C8000/C9000Xerox · Versalink C8000WXerox · WorkCentre 6515