VYPR
Unrated severityNVD Advisory· Published Mar 20, 2011· Updated Apr 29, 2026

CVE-2011-1025

CVE-2011-1025

Description

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

Affected products

18
  • OpenLDAP/Openldap18 versions
    cpe:2.3:a:openldap:openldap:2.4.6:*:*:*:*:*:*:*+ 17 more
    • cpe:2.3:a:openldap:openldap:2.4.6:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.8:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.9:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.10:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.12:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.13:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.14:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.15:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.16:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.17:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.18:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.19:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.20:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.21:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:*
    • cpe:2.3:a:openldap:openldap:2.4.23:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.