CVE-2023-0922Cleartext Transmission of Sensitive Info in Samba

Severity
5.9MEDIUMNVD
OSV6.5
EPSS
0.2%
top 54.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3
Latest updateApr 11

Description

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

NVDsamba/samba4.0.04.16.10+2
Debiansamba/samba< 2:4.17.7+dfsg-1+2
Ubuntusamba/samba< 2:4.15.13+dfsg-0ubuntu0.20.04.2+1
CVEListV5samba/sambasamba 4.18.1, samba 4.17.7, samba 4.16.10

🔴Vulnerability Details

4
GHSA
GHSA-v9cf-pxq6-w297: The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only conne2023-04-04
OSV
samba vulnerabilities2023-04-03
OSV
CVE-2023-0922: The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only conne2023-04-03
CVEList
CVE-2023-0922: The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only conne2023-04-03

📋Vendor Advisories

4
Microsoft
The Samba AD DC administration tool when operating against a remote LDAP server will by default send new or reset passwords over a signed-only connection.2023-04-11
Ubuntu
Samba vulnerabilities2023-04-03
Red Hat
samba: AD DC admin tool samba-tool sends passwords in cleartext2023-03-29
Debian
CVE-2023-0922: samba - The Samba AD DC administration tool, when operating against a remote LDAP server...2023