Impact
The flaw in 389-ds-base stems from the server retaining plaintext bytes that a client has already sent during a StartTLS upgrade. An on‑path attacker can inject a crafted LDAP message that is processed after TLS is established. If the injected message shares the same messageID as the client’s pending operation, the server returns the attacker’s response to the client, making a failed authentication appear to succeed. This effectively allows the attacker to authenticate as any user without valid credentials, a classic authentication bypass scenario described by CWE‑923.
Affected Systems
Affected systems include Red Hat Directory Server versions 11, 12, and 13, as well as Red Hat Enterprise Linux distributions 10, 6, 7, 8, and 9, which expose the vulnerable LDAP service on port 389.
Risk and Exploitability
The CVSS score of 9 indicates critical severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, but an attacker with the ability to interpose traffic on the LDAP port can exploit the buffer‑retention flaw easily. The attack requires only network position, not privileged access, and can be performed over standard LDAP traffic. Because no official patch exists, the exploit remains viable for the entire set of affected products unless mitigated.
OpenCVE Enrichment