CVE-2013-5185Apple MAC OS X vulnerability

CWE-3102 documents2 sources
Severity
4.3MEDIUMNVD
EPSS
0.1%
top 66.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 24
Latest updateMay 17

Description

The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly process the minssf configuration setting, which allows remote attackers to obtain sensitive information by leveraging unintended weak encryption and sniffing the network.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapple/mac_os_x10.8.5+6

🔴Vulnerability Details

1
GHSA
GHSA-757p-x3jc-426r: The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 102022-05-17