CVE Vulnerabilities

CVE-2024-34162

Access to Critical Private Variable via Public Method

Published: Nov 26, 2024 | Modified: Nov 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to SIMPLE, the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

Weakness

The product defines a public method that reads or modifies a private variable.

Potential Mitigations

References