bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.044
EPSS Ranking 90.2%