CVE-2013-0214
published 2013-02-02CVE-2013-0214: Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before…
PriorityP426medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
1.91%
77.6th percentile
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
Affected
146 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:3.6.6-5 (bookworm) | samba 2:3.6.6-5 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h9pm-h729-wj6q: Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3
ghsa_unreviewed·2022-05-05
CVE-2013-0214 [MEDIUM] CWE-352 GHSA-h9pm-h729-wj6q: Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
OSV
samba vulnerabilities
osv·2016-03-08·CVSS 5.1
CVE-2015-7560 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink
paths. A remote attacker could use this issue to overwrite the ownership of
ACLs using symlinks. (CVE-2015-7560)
Garming Sam and Douglas Bagnall discovered that the Samba internal DNS
server incorrectly handled certain DNS TXT records. A remote attacker could
use this issue to cause Samba to crash, resulting in a denial of service,
or possibly obtain uninitialized memory contents. This issue only applied
to Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771)
It was discovered that the Samba Web Administration Tool (SWAT) was
vulnerable to clickjacking and cross-site request forgery attacks. This
issue only affected Ubuntu 12.04 LTS. (CVE-2013-0213, CVE-2013-0214)
OSV
CVE-2013-0214: Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3
osv·2013-02-02·CVSS 5.1
CVE-2013-0214 [MEDIUM] CVE-2013-0214: Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
CISA ICS
Omron NS Series HMI Vulnerabilities
cisa_ics·2019-01-31
Omron NS Series HMI Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Omron NS Series HMI Vulnerabilities
Last RevisedJanuary 31, 2019
Alert CodeICSA-14-203-01
## OVERVIEW
Researcher Joel Sevilleja Febrer of S2 Grupo has identified multiple vulnerabilities in Omron Corporation’s NS series human-machine interface (HMI) terminals. Omron Corporation has produced an update that mitigates these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
The following Omron Corporation products are affected:
- NS15 Version 8.1xx - 8.68x,
- NS12 Version 8.1xx - 8.68x,
- NS10 Version 8.1xx - 8.68x,
- NS8 Version 8.1xx -
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2016-03-08·CVSS 5.1
CVE-2013-0213 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink
paths. A remote attacker could use this issue to overwrite the ownership of
ACLs using symlinks. (CVE-2015-7560)
Garming Sam and Douglas Bagnall discovered that the Samba internal DNS
server incorrectly handled certain DNS TXT records. A remote attacker could
use this issue to cause Samba to crash, resulting in a denial of service,
or possibly obtain uninitialized memory contents. This issue only applied
to Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771)
It was discovered that the Samba Web Administration Tool (SWAT) was
vulnerable to clickjacking and cross-site request forgery attacks. This
issue only affected Ubuntu 12.04 LTS.
Red Hat
samba: cross-site request forgery vulnerability in SWAT
vendor_redhat·2013-01-30·CVSS 5.1
CVE-2013-0214 [MEDIUM] CWE-352 samba: cross-site request forgery vulnerability in SWAT
samba: cross-site request forgery vulnerability in SWAT
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
Debian
CVE-2013-0214: samba - Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration ...
vendor_debian·2013·CVSS 5.1
CVE-2013-0214 [MEDIUM] CVE-2013-0214: samba - Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration ...
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
Scope: local
bookworm: resolved (fixed in 2:3.6.6-5)
bullseye: resolved (fixed in 2:3.6.6-5)
forky: resolved (fixed in 2:3.6.6-5)
sid: resolved (fixed in 2:3.6.6-5)
trixie: resolved (fixed in 2:3.6.6-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0213 CVE-2013-0214 samba various flaws [fedora-all]
bugzilla·2013-01-30·CVSS 5.1
CVE-2013-0213 [MEDIUM] CVE-2013-0213 CVE-2013-0214 samba various flaws [fedora-all]
CVE-2013-0213 CVE-2013-0214 samba various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple sup
Bugzilla
CVE-2013-0213 CVE-2013-0214 samba4 various flaws [fedora-17]
bugzilla·2013-01-30·CVSS 5.1
CVE-2013-0213 [MEDIUM] CVE-2013-0213 CVE-2013-0214 samba4 various flaws [fedora-17]
CVE-2013-0213 CVE-2013-0214 samba4 various flaws [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-17 tracking bug for samba4: see block
Bugzilla
CVE-2013-0214 samba: cross-site request forgery vulnerability in SWAT
bugzilla·2013-01-30·CVSS 6.8
CVE-2013-0214 [MEDIUM] CVE-2013-0214 samba: cross-site request forgery vulnerability in SWAT
CVE-2013-0214 samba: cross-site request forgery vulnerability in SWAT
It was reported [1] that Samba's SWAT web configuration interface suffered from a potential cross-site request forgery (CSRF) vulnerability.
This is being fixed by using a random nonce stored in secrets.tdb.
[1] https://bugzilla.samba.org/show_bug.cgi?id=9577
Discussion:
Acknowledgements:
Red Hat would like to thank the Samba project for reporting this issue. Upstream acknowledges Jann Horn as the original reporter.
---
This has been corrected in upstream versions 4.0.2, 3.6.12, and 3.5.21.
External References:
http://www.samba.org/samba/history/samba-4.0.2.html
---
Created samba4 tracking bugs for this issue
Affects: fedora-17 [bug 906003]
---
Created samba tracking bugs for this issue
Affects: fedora-al
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00033.htmlhttp://osvdb.org/89627http://rhn.redhat.com/errata/RHSA-2013-1310.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1542.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0305.htmlhttp://www.debian.org/security/2013/dsa-2617http://www.samba.org/samba/security/CVE-2013-0214http://www.securityfocus.com/bid/57631http://www.ubuntu.com/usn/USN-2922-1https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00033.htmlhttp://osvdb.org/89627http://rhn.redhat.com/errata/RHSA-2013-1310.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1542.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0305.htmlhttp://www.debian.org/security/2013/dsa-2617http://www.samba.org/samba/security/CVE-2013-0214http://www.securityfocus.com/bid/57631http://www.ubuntu.com/usn/USN-2922-1https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993
2013-02-02
Published