// For flags

CVE-2023-35833

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password to be (re)entered. This results in exposing cleartext credentials when connecting to a rogue LDAP server. NOTE: the vendor originally reported this as a security issue but then reconsidered because of the requirement for Admin access in order to change the configuration.

** EN DISPUTA ** Se descubrió un problema en YSoft SAFEQ 6 Server antes de la versión 6.0.82. Al modificar la URL de la configuración del servidor LDAP de LDAPS a LDAP, el sistema no requiere que se (re)ingrese la contraseña. Esto da como resultado la exposición de credenciales en texto claro al conectarse a un servidor LDAP no autorizado. NOTA: el proveedor informó originalmente esto como un problema de seguridad, pero luego lo reconsideró debido al requisito de acceso de administrador para poder cambiar la configuración.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-06-18 CVE Reserved
  • 2023-07-13 CVE Published
  • 2024-07-19 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ysoft
Search vendor "Ysoft"
Safeq Server
Search vendor "Ysoft" for product "Safeq Server"
>= 6.0 < 6.0.82
Search vendor "Ysoft" for product "Safeq Server" and version " >= 6.0 < 6.0.82"
-
Affected