Lucene search

K
nvd[email protected]NVD:CVE-2013-1863
HistoryMar 19, 2013 - 5:55 p.m.

CVE-2013-1863

2013-03-1917:55:02
CWE-264
web.nvd.nist.gov
6

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.002

Percentile

54.6%

Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which allows remote authenticated users to read, modify, create, or delete arbitrary files via standard filesystem operations.

Affected configurations

Nvd
Node
sambasambaMatch4.0.0
OR
sambasambaMatch4.0.1
OR
sambasambaMatch4.0.2
OR
sambasambaMatch4.0.3
VendorProductVersionCPE
sambasamba4.0.0cpe:2.3:a:samba:samba:4.0.0:*:*:*:*:*:*:*
sambasamba4.0.1cpe:2.3:a:samba:samba:4.0.1:*:*:*:*:*:*:*
sambasamba4.0.2cpe:2.3:a:samba:samba:4.0.2:*:*:*:*:*:*:*
sambasamba4.0.3cpe:2.3:a:samba:samba:4.0.3:*:*:*:*:*:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.002

Percentile

54.6%