Vulnerability record · CVE-2020-36222 · published 26 January 2021
CVE-2020-36222: OpenLDAP slapd assertion failure in saslAuthzTo validation causes DoS
Openldap · Openldap
OpenLDAP before 2.4.57 contains a flaw in slapd's saslAuthzTo validation that triggers an assertion failure, crashing the daemon. Because slapd is the core directory server, a crash takes down authentication and directory services for everything relying on it.
Description
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityNetwork-reachable, unauthenticated denial of service against a core directory service, with very high EPSS despite no KEV listing.
What it is
OpenLDAP before 2.4.57 contains a flaw in slapd's saslAuthzTo validation that triggers an assertion failure, crashing the daemon. Because slapd is the core directory server, a crash takes down authentication and directory services for everything relying on it.
Impact
An attacker can crash slapd, causing a denial of service against the LDAP directory and any systems depending on it for authentication or lookups. No data confidentiality or integrity impact is described.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the flaw is triggered by sending crafted requests to the LDAP service. No authentication is required per the vector.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high at 0.777 (99.5th percentile), indicating elevated likelihood of exploitation activity. Reference tags are advisory, patch and issue-tracking only, with no public exploit tag.
What to do
- Upgrade OpenLDAP to 2.4.57 or later, applying the vendor commits referenced in the advisory.
- Apply the Debian and Apple vendor updates for affected distributions and macOS builds.
- Restrict network access to slapd ports to trusted clients only.
- Monitor slapd for unexpected restarts or crashes and alert on assertion failures.
Detection
- Watch slapd logs for assertion failures or abnormal process termination.
- Alert on unexpected slapd restarts or service downtime via process and port monitoring.
- Baseline and monitor LDAP request rates for anomalous or malformed saslAuthzTo-related traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-36222 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-36222), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.