Lucene search

K
ibmIBM2F98E1572BD765580F3BD7EF9F96672519117A7F1D1F30D192EB70DE66AC7455
HistoryNov 09, 2023 - 5:55 a.m.

Security Bulletin: A vulnerability in Samba affects IBM Storage Scale SMB protocol access method (CVE-2022-2127)

2023-11-0905:55:11
www.ibm.com
20
samba
ibm storage scale
smb protocol
vulnerability
remote attacker
code execution
denial of service
ibm storage scale 5.1.0.0
ibm storage scale 5.1.8.1
cve-2022-2127
out-of-bounds read
fix
ibm storage scale v5.1.8.2
ibm storage scale v5.1.9.0

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

41.5%

Summary

A Samba vulnerability affects IBM Storage Scale SMB protocol access method that could allow a remote authenticated attacker to execute arbitrary code or denial of service on the system.

Vulnerability Details

CVEID:CVE-2022-2127
**DESCRIPTION:**Samba is vulnerable to a denial of service, caused by an out-of-bounds read flaw in winbind AUTH_CRAP. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/261923 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Storage Scale 5.1.0.0 - 5.1.8.1

Remediation/Fixes

For IBM Storage Scale V5.1.0.0 through V5.1.8.1, apply

V5.1.8.2 or later available from FixCentral at:

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Storage+Scale&release=5.1.8&platform=All&function=all

V5.1.9.0 or later available from FixCentral at:

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Storage+Scale&release=5.1.9&platform=All&function=all

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmscale_out_network_attached_storageMatch5.1.
VendorProductVersionCPE
ibmscale_out_network_attached_storage5.1.cpe:2.3:h:ibm:scale_out_network_attached_storage:5.1.:*:*:*:*:*:*:*

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

41.5%