Логотип exploitDog
bind:CVE-2019-19747
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-19747

Количество 2

Количество 2

nvd логотип

CVE-2019-19747

около 6 лет назад

NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-w4wf-2w6j-48rg

больше 3 лет назад

NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-19747

NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).

CVSS3: 9.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-w4wf-2w6j-48rg

NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу