Vulnerability CVE-2023-35833


Published: 2023-07-13

Description:
An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password to be (re)entered. This results in exposing cleartext credentials when connecting to a rogue LDAP server.

 References:
https://ysoft.com
https://www.ysoft.com/en/legal/ldaps-encryption-downgrade-attack-vulnerability

Copyright 2026, cxsecurity.com

 

Back to Top