CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
73.5%
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the “unix password sync” option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.
Vendor | Product | Version | CPE |
---|---|---|---|
hp | cifs-9000_server | * | cpe:2.3:a:hp:cifs-9000_server:*:*:*:*:*:*:*:* |