cbcvebase.
CVE-2013-0454
published 2013-03-26

CVE-2013-0454: The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other…

PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
2.98%
85.9th percentile
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiansamba< samba 2:3.6.6-1 (bookworm)samba 2:3.6.6-1 (bookworm)
ibmstorwize
sambasamba<= 3.6.5
sambasamba
sambasamba
sambasamba
sambasamba
sambasamba
sambasamba>= 0 < 2:3.6.6-12:3.6.6-1
sambasamba>= 0 < 2:3.6.6-12:3.6.6-1
sambasamba>= 0 < 2:3.6.6-12:3.6.6-1
sambasamba>= 0 < 2:3.6.6-12:3.6.6-1

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.