Impact
A flaw in 389 Directory Server allows an attacker to install a stale identity carried in a Cyrus SASL auxiliary property during a SASL PLAIN bind. By first attempting a failed PLAIN bind as the Directory Manager with an incorrect password, then completing a separate bind (either SASL ANONYMOUS or a successful bind with a low‑privileged account), the server incorrectly grants Directory Manager privileges. This bypass of authentication can be used to obtain full administrative control of the directory service.
Affected Systems
The vulnerability affects Red Hat Directory Server versions 11, 12, and 13, as well as several Red Hat Enterprise Linux releases (6, 7, 8, 9, and 10). Users of these products should verify the installed version against the affected releases.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. EPSS is not available, but the absence of a KEV listing does not mitigate the risk because the attack chain requires only a single connection and does not rely on special privileges. The exploit can be performed remotely by an attacker who can initiate LDAP binds to the server. Once the stale identity is planted, no valid credentials are necessary, and full administrative access is granted. This makes the vulnerability highly actionable and potentially devastating for any exposed or unsecured directory service.
OpenCVE Enrichment