CVE-2019-5648
Last modified
CVE-2019-5648 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials. These steps can be used by any authenticated administrative user to expose the LDAP credentials configured in the LDAP connector over the network.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials. These steps can be used by any authenticated administrative user to expose the LDAP credentials configured in the LDAP connector over the network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Barracuda | Load Balancer Adc Firmware | <= 6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5648?
How severe is CVE-2019-5648?
How do I fix CVE-2019-5648?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5641Rapid7 InsightVM suffers from an information exposure issue …5.3
- CVE-2019-5642Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior su…3.3
- CVE-2019-5643Computing For Good's Basic Laboratory Information System (al…5.3
- CVE-2019-5644Computing For Good's Basic Laboratory Information System (al…9.8
- CVE-2019-5645By sending a specially crafted HTTP GET request to a listeni…7.5
- CVE-2019-5647The Chrome Plugin for Rapid7 AppSpider can incorrectly keep …7.1
- CVE-2019-5650Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5651Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5652Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5653Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5654Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5655Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2019-5648?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
