CVE-2023-1656 is a critical Cleartext Transmission of Sensitive Information vulnerability affecting ForgeRock OpenIDM and Java Remote Connector Server (RCS) LDAP Connector versions 1.5.20.9 through 1.5.20.13 across Windows, MacOS, and Linux. With a CVSS score of 7.5 (HIGH), this vulnerability allows remote attackers to intercept sensitive information due to unencrypted data transmission, potentially leading to the compromise of stolen credentials. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.5.20.9, < 1.5.20.14CPE matchmatch criteria | cpe:2.3:a:forgerock:ldap_connector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.