CVE detail
CVE-2005-2069 — CVE-2005-2069
Published 2005-06-30 · Modified 2026-06-16 · Vendor padl · Product nss_ldap · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0275
EPSS probability
exploitation probability, 30d
85.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References