Impact
The vulnerability is a hard‑coded LDAP credential flaw in TÜBİTAK BİLGEM’s Liderahenk application. Attackers can attempt common or default usernames and passwords to authenticate, giving them unauthorized access. This credential exposure allows the attacker to act with the privileges granted to the compromised account, potentially leading to full system compromise.
Affected Systems
TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk versions prior to 3.5.5 are vulnerable. The flaw exists in any build before the 3.5.5 release, regardless of deployment environment.
Risk and Exploitability
The flaw carries a high CVSS score of 9.1 and is listed as a credential exposure vulnerability (CWE‑798). Although no EPSS score is available, the absence of a KEV listing does not reduce the seriousness. The likely attack vector is through the LDAP authentication interface, where attackers can guess or use default credentials from any network location that can reach the application, making remote exploitation possible.
OpenCVE Enrichment