IM
IronMonkey Threat Research

CVE-2023-2953 HIGH

Published: 2023-05-30 | Last Modified: 2025-01-10 | Status: Modified

Description

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-476
[email protected] Secondary
en CWE-476
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-476

Affected Products

Vendor Product Version Update Type
openldap openldap 2.4 <built-in method update of dict object at 0x7fd36b1dd180> Application
redhat enterprise_linux 8.0 <built-in method update of dict object at 0x7fd340a1c1c0> Operating System
redhat enterprise_linux 9.0 <built-in method update of dict object at 0x7fd341be8500> Operating System
apple macos * <built-in method update of dict object at 0x7fd3855eb140> Operating System
apple macos * <built-in method update of dict object at 0x7fd36b1df640> Operating System
apple macos * <built-in method update of dict object at 0x7fd36b1dfc40> Operating System
netapp active_iq_unified_manager - <built-in method update of dict object at 0x7fd3105f9980> Application
netapp clustered_data_ontap - <built-in method update of dict object at 0x7fd36b13b700> Application
netapp ontap_tools - <built-in method update of dict object at 0x7fd340ac3e40> Application
netapp h300s_firmware - <built-in method update of dict object at 0x7fd36b1dce00> Operating System
netapp h500s_firmware - <built-in method update of dict object at 0x7fd38493ea80> Operating System
netapp h700s_firmware - <built-in method update of dict object at 0x7fd340a1e980> Operating System
netapp h410s_firmware - <built-in method update of dict object at 0x7fd3106d4c40> Operating System
netapp h410c_firmware - <built-in method update of dict object at 0x7fd386785640> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:openldap:openldap:2.4:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Yes cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:ontap_tools:-:*:*:*:*:vmware_vsphere:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

References