Impact
PEAKUP Technology Inc. PassGate contains an LDAP injection flaw where user-supplied input is inserted into an LDAP query CWE-90. The vulnerability enables manipulation of LDAP query syntax, and may lead to unauthorized retrieval or modification of directory entries - this is inferred from the description that the query can be altered, but the CVE data does not explicitly confirm the end result.
Affected Systems
All versions of PEAKUP PassGate through build 30042026 are affected, as noted by the vendor advisory.
Risk and Exploitability
The CVSS score of 8.2 signals high severity. The EPSS score is less than 1%, indicating a very low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread attacks yet. The likely attack vector involves network access to Pass LDAP queries can be submitted; this flaw that allows alteration of LDAP query syntax.
OpenCVE Enrichment