Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-0211

56
FAUCET Score

CVE-2010-0211 is a critical denial-of-service and potential arbitrary code execution vulnerability affecting OpenLDAP 2.4.22 and products like Apple, openSUSE, and VMware that incorporate it. The flaw stems from a missing return value check in the slap_modrdn2mods function, allowing remote attackers to trigger a segmentation fault and free an uninitialized pointer via malformed RDN strings in modrdn calls. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication, leading to high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog or showing active exploitation, a proof-of-concept exploit exists on ExploitDB, and it has garnered minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
2.4.22CPE matchmatch criteria
cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:*
4.1CPE matchmatch criteria
cpe:2.3:o:vmware:esxi:4.1:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*
>= 10.6.0, < 10.6.5CPE matchmatch criteria
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
29.24%
Probability of exploitation in next 30 days
EPSS Percentile
98.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-34348 · Jul 19, 2010
This CVE's current EPSS score of 0.2924 is in the 95th percentile among its peer group of 36,821 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openldap-0:2.2.13-12.el4_8.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openldap-0:2.3.43-12.el5_5.1
View patch

Vendor Advisories (1)

redhatCVE-2010-0211Important

openldap: modrdn processing uninitialized pointer free

Jul 19, 2010

References

kb.juniper.net / InfoCenter/index
Third Party Advisory
lists.apple.com / archives/security-announce/2010//Nov/msg00000.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2010-08/msg00001.html
Mailing List
secunia.com / advisories/40639
Broken LinkVendor Advisory
secunia.com / advisories/40677
Broken LinkVendor Advisory
secunia.com / advisories/40687
Broken LinkVendor Advisory
secunia.com / advisories/42787
Broken Link
security.gentoo.org / glsa/glsa-201406-36.xml
Third Party Advisory
support.apple.com / kb/HT4435
Issue Tracking
openldap.org / its/index.cgi/Software%20Bugs
Exploit
redhat.com / support/errata/RHSA-2010-0542.html
Broken Link
redhat.com / support/errata/RHSA-2010-0543.html
Broken Link
securityfocus.com / archive/1/515545/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/41770
Broken LinkExploitPatchThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
vmware.com / security/advisories/VMSA-2011-0001.html
Third Party Advisory
vupen.com / english/advisories/2010/1849
Broken LinkVendor Advisory
vupen.com / english/advisories/2010/1858
Broken LinkVendor Advisory
vupen.com / english/advisories/2011/0025
Broken Link