Impact
SSSD fails to treat an LDAP shadow expiration value of zero as an expired account, allowing a user who can present valid credentials for such an account to authenticate successfully. The weakness is an improper sign conversion (CWE-193) that permits bypass of access controls and persists unauthorized access after an account should be deactivated.
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, 9, 10 and Red Hat OpenShift Container Platform 4 are affected; specific impacted versions are not enumerated in the advisory.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by authenticating with a valid credential set tied to an LDAP account whose expiration attribute is set to zero, thereby bypassing the intended deactivation. The attack can be carried out over the network if LDAP credentials are available, and does not require privilege escalation beyond the granted account rights.
OpenCVE Enrichment