← volver
CVE-2021-3825criticalCWE-306

Missing Authorization Checks in LiderAhenk

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.6epss 1.6%
probabilidad de explotación
1.6%top 25% de las CVE
explotación observada
noninguna fuente lo reporta
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
TUBITAK · Lider