CVE-2023-33254

CVSS V2 None CVSS V3 None
Description
There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled LDAP server, clicks the Test Settings button, and captures the cleartext credentials.
Overview
  • CVE ID
  • CVE-2023-33254
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-05-21T22:15:15
  • Last Modified Date
  • 2023-05-21T22:15:15
History
Created Old Value New Value Data Type Notes
2023-05-21 23:00:28 Added to TrackCVE