CVE-2013-5185

EUVD-2013-5025
The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly process the minssf configuration setting, which allows remote attackers to obtain sensitive information by leveraging unintended weak encryption and sniffing the network.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Affected Products (NVD)
VendorProductVersion
applemac_os_x
𝑥
≤ 10.8.5
applemac_os_x
10.8.0
applemac_os_x
10.8.1
applemac_os_x
10.8.2
applemac_os_x
10.8.3
applemac_os_x
10.8.4
applemac_os_x
10.8.5
𝑥
= Vulnerable software versions
Common Weakness Enumeration