PT-2024-13923 · Novell+2 · Novell Ldap+2

Published

2024-01-31

·

Updated

2024-02-15

·

CVE-2023-50356

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions AREAL Topkapi Vision (Server) (affected versions not specified)
Description The issue allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from logging in due to improper certificate validation in SSL connections to some LDAP servers, including NOVELL and Synology LDAP servers. This enables a man-in-the-middle attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2023-50356

Affected Products

Areal Topkapi Vision
Novell Ldap
Synology Ldap