CVE-2024-5953 describes a denial of service vulnerability in the 389-ds-base LDAP server, allowing an authenticated user to crash the server by logging in with a malformed password hash. It has a CVSS score of 5.7 (Medium), indicating a low attack complexity and requiring local network access and low privileges to achieve high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Directory Server 11.7 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Directory Server 11.9 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Directory Server 12.4 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Directory Server 11.5 E4S For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Directory Server 12.2 EUS For RHEL 9 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.