Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials. These steps can be used by any authenticated administrative user to expose the LDAP credentials configured in the LDAP connector over the network.
References
Link | Resource |
---|---|
https://blog.rapid7.com/2020/03/05/r7-2019-39-cve-2019-5648-ldap-credential-exposure-in-barracuda-load-balancer-adc-fixed/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-03-12 06:15
Updated : 2020-03-12 09:35
NVD link : CVE-2019-5648
Mitre link : CVE-2019-5648
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
barracuda
- load_balancer_adc
- load_balancer_adc_firmware