Lucene search

K
nvd[email protected]NVD:CVE-2013-0454
HistoryMar 26, 2013 - 9:55 p.m.

CVE-2013-0454

2013-03-2621:55:01
CWE-264
web.nvd.nist.gov
4

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

52.3%

The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or “hide unreadable” parameter.

Affected configurations

Nvd
Node
canonicalubuntu_linuxMatch12.04-lts
Node
sambasambaRange3.6.5
OR
sambasambaMatch3.6.0
OR
sambasambaMatch3.6.1
OR
sambasambaMatch3.6.2
OR
sambasambaMatch3.6.3
OR
sambasambaMatch3.6.4
AND
ibmstorwizeMatchv70001.3
OR
ibmstorwizeMatchv70001.4
VendorProductVersionCPE
canonicalubuntu_linux12.04cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
sambasamba*cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
sambasamba3.6.0cpe:2.3:a:samba:samba:3.6.0:*:*:*:*:*:*:*
sambasamba3.6.1cpe:2.3:a:samba:samba:3.6.1:*:*:*:*:*:*:*
sambasamba3.6.2cpe:2.3:a:samba:samba:3.6.2:*:*:*:*:*:*:*
sambasamba3.6.3cpe:2.3:a:samba:samba:3.6.3:*:*:*:*:*:*:*
sambasamba3.6.4cpe:2.3:a:samba:samba:3.6.4:*:*:*:*:*:*:*
ibmstorwizev7000cpe:2.3:a:ibm:storwize:v7000:1.3:*:*:*:*:*:*
ibmstorwizev7000cpe:2.3:a:ibm:storwize:v7000:1.4:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

52.3%