CVE-2005-2069 describes a vulnerability in pam_ldap and nss_ldap when used with OpenLDAP. Specifically, if a client connects to an OpenLDAP slave using TLS and is then referred to a master server, the subsequent connection to the master may not use TLS, potentially exposing passwords in cleartext. This vulnerability has a CVSS score of 5.0, indicating a medium severity risk with low attack complexity, allowing remote attackers to sniff sensitive information. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:padl:nss_ldap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:padl:pam_ldap:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2005-2069
Sep 8, 2020security flaw
Jun 28, 2005pam_ldap and nss_ldap when used with OpenLDAP and connecting to a slave using TLS does not use TLS for the subsequent connection if the client is referred to a master which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
Jun 2, 2005