
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-36230 is a vulnerability discovered in OpenLDAP versions before 2.4.57 that leads to an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element function. The vulnerability was disclosed on January 26, 2021 (NVD).
The vulnerability is caused by an assertion failure in the ber_next_element function within decode.c when parsing X.509 DN certificates. It has a CVSS v3.1 Base Score of 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network accessibility with no privileges required (NVD, NetApp Advisory).
When successfully exploited, this vulnerability results in a denial of service condition through the crashing of the slapd daemon. The vulnerability affects the availability of the system but does not impact confidentiality or integrity (NetApp Advisory).
The vulnerability can be triggered by an unauthenticated remote attacker sending specially crafted packets to the affected system. A proof-of-concept exploit has been documented that demonstrates the assertion failure (OpenLDAP Bug).
The vulnerability was fixed in OpenLDAP version 2.4.57. The fix involves checking for invalid BER after RDN count in the ldap_X509dn2bv function (OpenLDAP Commit). Various vendors have released patches for their affected products, including Apple, Debian, and NetApp (Debian Advisory, Apple Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."