Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37421 | There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled LDAP server, clicks the Test Settings button, and captures the cleartext credentials. |
Fri, 31 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-31T15:33:33.661Z
Reserved: 2023-05-21T00:00:00.000Z
Link: CVE-2023-33254
Updated: 2024-08-02T15:39:36.252Z
Status : Modified
Published: 2023-05-21T22:15:15.067
Modified: 2025-01-31T16:15:30.103
Link: CVE-2023-33254
No data.
OpenCVE Enrichment
No data.
EUVD