Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-5953

18
FAUCET Score

CVE-2024-5953 describes a denial of service vulnerability in the 389-ds-base LDAP server, allowing an authenticated user to crash the server by logging in with a malformed password hash. It has a CVSS score of 5.7 (Medium), indicating a low attack complexity and requiring local network access and low privileges to achieve high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Directory Server 11.7 For RHEL 8
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Directory Server 11.9 For RHEL 8
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Directory Server 12.4 For RHEL 9
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Directory Server 11.5 E4S For RHEL 8
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Directory Server 12.2 EUS For RHEL 9
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

5.7MEDIUM

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.1
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 72nd percentile among its peer group of 314 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

redhatpatch availablevia redhat_api
Product: Red Hat Directory Server 11.5 E4S for RHEL 8Fixed in: redhat-ds:11-8060020250210084424.0ca98e7e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Directory Server 11.7 for RHEL 8Fixed in: redhat-ds:11-8080020240909040333.f969626e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Directory Server 11.9 for RHEL 8Fixed in: redhat-ds:11-8100020240902112955.37ed7c03
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Directory Server 12.2 EUS for RHEL 9Fixed in: redhat-ds:12-9020020240916150035.1674d574
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Directory Server 12.4 for RHEL 9Fixed in: redhat-ds:12-9040020240723122852.1674d574
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: 389-ds-base-0:1.3.11.1-6.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: 389-ds:1.4-8100020240910065753.25e700aa
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: 389-ds:1.4-8080020240807050952.6dbb3803
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: 389-ds-base-0:2.4.5-9.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: 389-ds-base-0:2.2.4-9.el9_2
View patch

Vendor Advisories (1)

redhatCVE-2024-5953Moderate

389-ds-base: Malformed userPassword hash may cause Denial of Service

Jun 13, 2024

References

lists.debian.org / debian-lts-announce/2025/01/msg00015.html
access.redhat.com / errata/RHSA-2024:4633
access.redhat.com / errata/RHSA-2024:4997
access.redhat.com / errata/RHSA-2024:5192
access.redhat.com / errata/RHSA-2024:5690
access.redhat.com / errata/RHSA-2024:6153
access.redhat.com / errata/RHSA-2024:6568
access.redhat.com / errata/RHSA-2024:6569
access.redhat.com / errata/RHSA-2024:6576
access.redhat.com / errata/RHSA-2024:7458
access.redhat.com / errata/RHSA-2025:1632
access.redhat.com / security/cve/CVE-2024-5953
bugzilla.redhat.com / show_bug.cgi