CVE-2013-5185

The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly process the minssf configuration setting, which allows remote attackers to obtain sensitive information by leveraging unintended weak encryption and sniffing the network.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
appleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
applemac_os_x
𝑥
≤ 10.8.5
applemac_os_x
10.8.0
applemac_os_x
10.8.1
applemac_os_x
10.8.2
applemac_os_x
10.8.3
applemac_os_x
10.8.4
applemac_os_x
10.8.5
𝑥
= Vulnerable software versions
Common Weakness Enumeration