Medium severity6.5NVD Advisory· Published Mar 12, 2020· Updated Jun 17, 2026
CVE-2019-5648
CVE-2019-5648
Description
Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials. These steps can be used by any authenticated administrative user to expose the LDAP credentials configured in the LDAP connector over the network.
Affected products
3- cpe:2.3:o:barracuda:load_balancer_adc_firmware:*:*:*:*:*:*:*:*Range: <=6.4
<=v6.4+ 1 more
- (no CPE)range: <=v6.4
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- blog.rapid7.com/2020/03/05/r7-2019-39-cve-2019-5648-ldap-credential-exposure-in-barracuda-load-balancer-adc-fixed/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.