CVE-2023-35833
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password to be (re)entered. This results in exposing cleartext credentials when connecting to a rogue LDAP server. NOTE: the vendor originally reported this as a security issue but then reconsidered because of the requirement for Admin access in order to change the configuration.
** EN DISPUTA ** Se descubrió un problema en YSoft SAFEQ 6 Server antes de la versión 6.0.82. Al modificar la URL de la configuración del servidor LDAP de LDAPS a LDAP, el sistema no requiere que se (re)ingrese la contraseña. Esto da como resultado la exposición de credenciales en texto claro al conectarse a un servidor LDAP no autorizado. NOTA: el proveedor informó originalmente esto como un problema de seguridad, pero luego lo reconsideró debido al requisito de acceso de administrador para poder cambiar la configuración.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-06-18 CVE Reserved
- 2023-07-13 CVE Published
- 2024-10-30 CVE Updated
- 2024-12-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://ysoft.com | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ysoft.com/en/legal/ldaps-encryption-downgrade-attack-vulnerability | 2024-05-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ysoft Search vendor "Ysoft" | Safeq Server Search vendor "Ysoft" for product "Safeq Server" | >= 6.0 < 6.0.82 Search vendor "Ysoft" for product "Safeq Server" and version " >= 6.0 < 6.0.82" | - |
Affected
|