cbcvebase.
CVE-2021-20251
published 2023-03-06

CVE-2021-20251: A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are…

PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.76%
51.4th percentile
A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiansamba< samba 2:4.17.2+dfsg-3 (bookworm)samba 2:4.17.2+dfsg-3 (bookworm)
fedoraprojectfedora
msrcazl3_samba_4.18.3-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
sambasamba
sambasamba>= 0 < 2:4.17.2+dfsg-32:4.17.2+dfsg-3
sambasamba>= 0 < 2:4.17.2+dfsg-32:4.17.2+dfsg-3
sambasamba>= 0 < 2:4.17.2+dfsg-32:4.17.2+dfsg-3
sambasamba>= 0 < 2:4.13.17~dfsg-0ubuntu1.20.04.52:4.13.17~dfsg-0ubuntu1.20.04.5
sambasamba>= 0 < 2:4.13.17~dfsg-0ubuntu1.20.04.42:4.13.17~dfsg-0ubuntu1.20.04.4
sambasamba>= 0 < 2:4.15.13+dfsg-0ubuntu12:4.15.13+dfsg-0ubuntu1
sambasamba>= 4.1.0 < 4.16.84.16.8
sambasamba>= 4.17.0 < 4.17.44.17.4

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.