CVE-2021-3825

CRITICAL

LiderAhenk <2.1.15 - Info Disclosure

Title source: llm
STIX 2.1

Description

On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.

References (3)

Core 3
Core References
Third Party Advisory government-resource broken-link
https://www.usom.gov.tr/bildirim/tr-21-0795
Exploit, Third Party Advisory x_refsource_confirm
https://pentest.blog/liderahenk-0day-all-your-pardus-clients-belongs-to-me/

Scores

CVSS v3 9.6
EPSS 0.0157
EPSS Percentile 72.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (2)
pardus/liderahenk < 2.1.15
TUBITAK/Lider unspecified - 2.1.16
Published Oct 01, 2021
Tracked Since Feb 18, 2026