CVE-2020-25692: Netapp Cloud Backup

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.

Affected products

  • Netapp Cloud Backup: affected versions not specified
  • Netapp Solidfire Baseboard Management Controller Firmware: affected versions not specified
  • Openldap Openldap: before 2.4.55 (fixed in 2.4.55)
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only

Published 2020-12-08. Last modified 2026-06-17.