CVE-2020-25692: Netapp Cloud Backup
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.
Affected products
- Netapp Cloud Backup: affected versions not specified
- Netapp Solidfire Baseboard Management Controller Firmware: affected versions not specified
- Openldap Openldap: before 2.4.55 (fixed in 2.4.55)
- Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only
Published 2020-12-08. Last modified 2026-06-17.