Lucene search

K
cvelistRedhatCVELIST:CVE-2021-23192
HistoryMar 02, 2022 - 12:00 a.m.

CVE-2021-23192

2022-03-0200:00:00
CWE-20
redhat
www.cve.org
1

8.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.6%

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "samba",
    "versions": [
      {
        "version": "Affects samba v4.10.0 to 4.15.1, Fixed in samba v4.15.2, v4.14.10 and v4.13.14.",
        "status": "affected"
      }
    ]
  }
]