The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
                
            Metrics
Affected Vendors & Products
References
        History
                    Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Tue, 10 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 26 Nov 2024 07:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]. | |
| Weaknesses | CWE-767 | |
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: jpcert
Published: 2024-11-26T07:37:57.671Z
Updated: 2024-12-10T15:43:40.628Z
Reserved: 2024-05-22T09:00:13.769Z
Link: CVE-2024-34162
Updated: 2024-12-10T15:43:37.027Z
Status : Received
Published: 2024-11-26T08:15:06.123
Modified: 2024-11-26T08:15:06.123
Link: CVE-2024-34162
No data.