๐Ÿ” CVE Alert

CVE-2023-4154

HIGH 7.5

Samba: ad dc password exposure to privileged users and rodcs

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords. Even in a default setup, RODC DC accounts, which should only replicate some passwords, can gain access to all domain secrets, including the vital krbtgt, effectively eliminating the RODC / DC distinction. Furthermore, the vulnerability fails to account for error conditions (fail open), like out-of-memory situations, potentially granting access to secret attributes, even under low-privileged attacker influence.

CWE CWE-787
Vendor n/a
Product samba
Published Nov 7, 2023
Last Updated Aug 2, 2024
Stay Ahead of the Next One

Get instant alerts for n/a samba

Be the first to know when new high vulnerabilities affecting n/a samba are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

n/a / samba
All versions affected
Red Hat / Red Hat Enterprise Linux 6
All versions affected
Red Hat / Red Hat Enterprise Linux 6
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Storage 3
All versions affected
Fedora / Fedora
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2023-4154 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2241883 bugzilla.samba.org: https://bugzilla.samba.org/show_bug.cgi?id=15424 security.netapp.com: https://security.netapp.com/advisory/ntap-20231124-0002/ samba.org: https://www.samba.org/samba/security/CVE-2023-4154.html