← Vulnerability feed

Vulnerability record · CVE-2017-7551 · published 16 August 2017

CVE-2017-7551: Fedoraproject 389 directory server error message information leak vulnerability

Fedoraproject · 389 Directory Server

389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.

9.8 CVSS 3.0 Critical EPSS 1.4% · top 28.0% CWE-209 · Error message information leakCWE-640 · Weak password recovery
9.8CVSS 3.0 base score, v2 5.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7551 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-15135Fedoraproject 389 directory server improper authentication vulnerabilityIt was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during th…EPSS 3.8%7.5CVE-2019-10171Fedoraproject 389 directory server allocation without limits vulnerabilityIt was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would…EPSS 1.4%7.5CVE-2019-3883Fedoraproject 389 directory server vulnerabilityIn 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout'…EPSS 8.2%7.5CVE-2018-14648Fedoraproject 389 directory server uncontrolled resource consumption vulnerabilityA flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An un…EPSS 6.3%7.5CVE-2018-14638Fedoraproject 389 directory server uncontrolled resource consumption vulnerabilityA flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connec…EPSS 2.7%7.5CVE-2018-14624Fedoraproject 389 directory server improper input validation vulnerabilityA vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly u…EPSS 2.4%7.5CVE-2018-1089Fedoraproject 389 directory server heap-based buffer overflow vulnerability389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading …EPSS 4.1%7.5CVE-2017-2591Fedoraproject 389 directory server heap-based buffer overflow vulnerability389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute …EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2017-7551), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.