{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-04T12:15:46.844","vulnerabilities":[{"cve":{"id":"CVE-2021-3825","sourceIdentifier":"iletisim@usom.gov.tr","published":"2021-10-01T15:15:07.883","lastModified":"2024-11-21T06:22:32.840","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials."},{"lang":"es","value":"En la versión 2.1.15 y por debajo del módulo Lider del software LiderAhenk son filtradas sus configuraciones por medio de una API no segura. Un atacante con acceso a la API de configuraciones podría conseguir credenciales LDAP válidas"}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pardus:liderahenk:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1.15","matchCriteriaId":"86A4CE56-CF14-4247-B7B6-26582A6E5BC8"}]}]}],"references":[{"url":"https://pentest.blog/liderahenk-0day-all-your-pardus-clients-belongs-to-me/","source":"iletisim@usom.gov.tr","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.usom.gov.tr/bildirim/tr-21-0795","source":"iletisim@usom.gov.tr","tags":["Third Party Advisory"]},{"url":"https://pentest.blog/liderahenk-0day-all-your-pardus-clients-belongs-to-me/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.usom.gov.tr/bildirim/tr-21-0795","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}