Medium severity6.5NVD Advisory· Published May 21, 2023· Updated Jun 17, 2026
CVE-2023-33254
CVE-2023-33254
Description
There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled LDAP server, clicks the Test Settings button, and captures the cleartext credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:quest:kace_systems_deployment_appliance:9.0.146:*:*:*:*:*:*:*
- KACE/KACE Systems Deployment and Remote Site appliancesdescription
- Range: = 9.0.146
Patches
Vulnerability mechanics
References
1- www.stevencampbell.info/KACE-LDAP-Bind-Credential-Exposure/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.