CVE-2020-17477: Univention Ucs@school

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests. For example, a teacher can gain administrator access via an NTLM hash.

Affected products

Published 2023-10-26. Last modified 2026-06-17.