CVE-2005-3170

5.0
MEDIUMCVSS v3.1 Base Score
1.04%
LOW RiskEPSS (63rd percentile)

The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.

Published: 10/6/2005
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

5MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

CVSS v2 Score

5.1

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

1.04%LOW Exploitation Risk
63rd percentile

This vulnerability has a 1.04% probability of being exploited in the next 30 days, ranking higher than 63% of all scored CVEs.

CWE Classification

Advertisement