CyberRota Analysis
AI-GeneratedThe vulnerability affects the 389 Directory Server during SASL PLAIN authentication, where the server improperly handles account-lock checks, allowing clients with valid credentials for locked accounts to maintain access without reverting the authenticated state. This flaw undermines account lock mechanisms, potentially enabling unauthorized access to sensitive data or resources. Organizations utilizing 389 Directory Server should prioritize addressing this issue to mitigate risks associated with unauthorized access.
Original NVD Description
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.
Related CVEs
Other vulnerabilities affecting the same vendor(s)