Juniper Networks IVE OS LDAP Referrals TLS Plaintext Password Vulnerability
BID:24575
Info
Juniper Networks IVE OS LDAP Referrals TLS Plaintext Password Vulnerability
| Bugtraq ID: | 24575 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2007 12:00AM |
| Updated: | Dec 18 2007 08:06PM |
| Credit: | Kenneth Golomb is credited with discovering this issue. |
| Vulnerable: |
Juniper IVE OS 6.0 Juniper IVE OS 5.4 |
| Not Vulnerable: |
Juniper IVE OS 6.0R3.12359 |
Discussion
Juniper Networks IVE OS LDAP Referrals TLS Plaintext Password Vulnerability
Juniper IVE OS is affected by a password-disclosure vulnerability when used with TLS.
This issue arises when a connection to a slave is established using TLS and the client is referred to a master. TLS is not used with this connection, which can allow an attacker to sniff network traffic and obtain user credentials.
Juniper IVE OS 5.4 and 6.0 are known to be vulnerable; other versions may be affected as well.
This issue may be related to BID: 14125 - OpenLDAP TLS Plaintext Password Vulnerability.
Juniper IVE OS is affected by a password-disclosure vulnerability when used with TLS.
This issue arises when a connection to a slave is established using TLS and the client is referred to a master. TLS is not used with this connection, which can allow an attacker to sniff network traffic and obtain user credentials.
Juniper IVE OS 5.4 and 6.0 are known to be vulnerable; other versions may be affected as well.
This issue may be related to BID: 14125 - OpenLDAP TLS Plaintext Password Vulnerability.
Exploit / POC
Juniper Networks IVE OS LDAP Referrals TLS Plaintext Password Vulnerability
An attacker may exploit this issue by using readily available network tools.
An attacker may exploit this issue by using readily available network tools.
Solution / Fix
Juniper Networks IVE OS LDAP Referrals TLS Plaintext Password Vulnerability
Solution:
UPDATE (December 14, 2007): Reports indicate that this issue is resolved in Juniper Networks IVE OS 6.0R3 Build # 12359; this has not been confirmed. Please contact the vendor for more information.
Solution:
UPDATE (December 14, 2007): Reports indicate that this issue is resolved in Juniper Networks IVE OS 6.0R3 Build # 12359; this has not been confirmed. Please contact the vendor for more information.
References
Juniper Networks IVE OS LDAP Referrals TLS Plaintext Password Vulnerability
References:
References:
- Juniper Networks Homepage (Juniper Networks)