LDAP Server NULL Bind Connection Information Disclosure
High
Vulnerability Details
**Description:**
The remote LDAP server allows anonymous access
## References
- https://www.tenable.com/plugins/nessus/10723
- https://ldap.com/ldapv3-wire-protocol-reference-bind
## Impact
information disclosure
## System Host(s)
████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
1. run $ `nmap -n -sV --script "ldap* and not brute" -p 389 ██████████`
check the response
## POC
██████
## Suggested Mitigation/Remediation Actions
Configure the service to disallow NULL BINDs.
Actions
View on HackerOneReport Stats
- Report ID: 1937235
- State: Closed
- Substate: resolved
- Upvotes: 7