LDAP Server NULL Bind Connection Information Disclosure

Disclosed: 2023-05-15 15:07:05 By 0xmaruf To deptofdefense
High
Vulnerability Details
**Description:** The remote LDAP server allows anonymous access ## References - https://www.tenable.com/plugins/nessus/10723 - https://ldap.com/ldapv3-wire-protocol-reference-bind ## Impact information disclosure ## System Host(s) ████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce 1. run $ `nmap -n -sV --script "ldap* and not brute" -p 389 ██████████` check the response ## POC ██████ ## Suggested Mitigation/Remediation Actions Configure the service to disallow NULL BINDs.
Actions
View on HackerOne
Report Stats
  • Report ID: 1937235
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report