Vulnerability Intelligence Report
LDAP Credential Exposure in Barracuda Load Balancer ADC
CVE-2019-5648
Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials. These steps can be used by any authenticated administrative user to expose the LDAP credentials configured in the LDAP connector over the network.
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
Exploitability:2.3
Impact Score:5.8
EPSS Probability:1.12%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-522 ↗Insufficiently Protected Credentials (CWE-522)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Barracuda | Load Balancer ADC | unspecified < 6.5 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.125%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Rapid7, Inc. · Vendor · USA |
| Reserved | 2019-01-07T00:00:00 |
| Published | 2020-03-12T13:00:16 |
| Patch Date | 2020-03-05 |
| Last Updated | 2024-09-17T01:21:54 |
Community Chatter & Buzz