PT-2024-25724 · Sharp+1 · Multiple Mfps

Pierre Barre

+1

·

Published

2024-11-26

·

Updated

2024-11-26

·

CVE-2024-34162

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions No specific product names, model numbers, or versions are mentioned in the provided descriptions.
Description The issue concerns the web interface of affected devices, which is designed to hide LDAP credentials from administrative users. However, when LDAP authentication is configured to "SIMPLE", the device communicates with the LDAP server in clear-text, allowing the LDAP password to be retrieved from this communication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-34162

Affected Products

Multiple Mfps