CVE-2015-5246 describes a high-severity vulnerability in the LDAP Authentication functionality of Foreman, allowing remote attackers to gain unauthorized access. This flaw arises from the interaction with Active Directory's password lifetime, enabling attackers with knowledge of old passwords to bypass authentication. The attack is network-based and complex, but if successful, it can lead to high confidentiality, integrity, and availability impacts. While no active exploitation or public exploit code is reported, and community discussion is minimal, the potential for significant compromise warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.9.0CPE matchmatch criteria | cpe:2.3:a:theforeman:foreman:1.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.