IM
IronMonkey Threat Research

CVE-2023-2953 HIGH

Published: 2023-05-30 | Last Modified: 2025-01-10 | Status: Modified

Description

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-476
[email protected] Secondary
en CWE-476
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-476

Affected Products

Vendor Product Version Update Type
openldap openldap 2.4 <built-in method update of dict object at 0x72a9b0dcf540> Application
redhat enterprise_linux 8.0 <built-in method update of dict object at 0x72a9a31fd480> Operating System
redhat enterprise_linux 9.0 <built-in method update of dict object at 0x72a999514dc0> Operating System
apple macos * <built-in method update of dict object at 0x72a9a31fd7c0> Operating System
apple macos * <built-in method update of dict object at 0x72a9b0b76ac0> Operating System
apple macos * <built-in method update of dict object at 0x72a9b0b77580> Operating System
netapp active_iq_unified_manager - <built-in method update of dict object at 0x72a9a31fca40> Application
netapp clustered_data_ontap - <built-in method update of dict object at 0x72a9a31fd180> Application
netapp ontap_tools - <built-in method update of dict object at 0x72a9a31ffe40> Application
netapp h300s_firmware - <built-in method update of dict object at 0x72a9b0b74c00> Operating System
netapp h500s_firmware - <built-in method update of dict object at 0x72a9a31fe800> Operating System
netapp h700s_firmware - <built-in method update of dict object at 0x72a9b0e0e400> Operating System
netapp h410s_firmware - <built-in method update of dict object at 0x72a9cc478e00> Operating System
netapp h410c_firmware - <built-in method update of dict object at 0x72a9b0b76e00> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:openldap:openldap:2.4:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Yes cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

References

Notification
Message here