CVE-2024-2199 is a denial of service vulnerability affecting the 389-ds-base LDAP server. An authenticated user can trigger a server crash by providing malformed input when modifying their userPassword. This vulnerability has a medium severity CVSS score of 5.7, indicating a low-complexity attack requiring local network access and user authentication, leading to high availability impact. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Directory Server 11.8 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Directory Server 11.9 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Directory Server 12.4 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Directory Server 11.5 E4S For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 8 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.