Lucene search

K
openvasCopyright (C) 2023 Greenbone AGOPENVAS:1361412562310104663
HistoryMar 31, 2023 - 12:00 a.m.

Samba Multiple Vulnerabilities (Mar 2023)

2023-03-3100:00:00
Copyright (C) 2023 Greenbone AG
plugins.openvas.org
8
samba
multiple vulnerabilities
cve-2023-0614
cve-2023-0922
update
version 4.16.10
version 4.17.7
version 4.18.1
security advisory

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

59.9%

Samba is prone to multiple vulnerabilities.

# SPDX-FileCopyrightText: 2023 Greenbone AG
# Some text descriptions might be excerpted from (a) referenced
# source(s), and are Copyright (C) by the respective right holder(s).
#
# SPDX-License-Identifier: GPL-2.0-only

CPE = "cpe:/a:samba:samba";

if(description)
{
  script_oid("1.3.6.1.4.1.25623.1.0.104663");
  script_version("2023-10-13T05:06:10+0000");
  script_tag(name:"last_modification", value:"2023-10-13 05:06:10 +0000 (Fri, 13 Oct 2023)");
  script_tag(name:"creation_date", value:"2023-03-31 09:52:43 +0000 (Fri, 31 Mar 2023)");
  script_tag(name:"cvss_base", value:"6.8");
  script_tag(name:"cvss_base_vector", value:"AV:N/AC:L/Au:S/C:C/I:N/A:N");
  script_tag(name:"severity_vector", value:"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N");
  script_tag(name:"severity_origin", value:"NVD");
  script_tag(name:"severity_date", value:"2023-04-10 18:38:00 +0000 (Mon, 10 Apr 2023)");

  script_cve_id("CVE-2023-0614", "CVE-2023-0922");

  script_tag(name:"qod_type", value:"remote_banner_unreliable");

  script_tag(name:"solution_type", value:"VendorFix");

  script_name("Samba Multiple Vulnerabilities (Mar 2023)");

  script_category(ACT_GATHER_INFO);

  script_copyright("Copyright (C) 2023 Greenbone AG");
  script_family("General");
  script_dependencies("smb_nativelanman.nasl", "gb_samba_detect.nasl");
  script_mandatory_keys("samba/smb_or_ssh/detected");

  script_tag(name:"summary", value:"Samba is prone to multiple vulnerabilities.");

  script_tag(name:"vuldetect", value:"Checks if a vulnerable version is present on the target host.");

  script_tag(name:"insight", value:"The following flaws exist:

  - CVE-2023-0614: Access controlled AD LDAP attributes can be discovered

  - CVE-2023-0922: Samba AD DC admin tool samba-tool sends passwords in cleartext");

  script_tag(name:"affected", value:"All versions of Samba since 4.0.");

  script_tag(name:"solution", value:"Update to version 4.16.10, 4.17.7, 4.18.1 or later.");

  script_xref(name:"URL", value:"https://www.samba.org/samba/security/CVE-2023-0614.html");
  script_xref(name:"URL", value:"https://www.samba.org/samba/security/CVE-2023-0922.html");

  exit(0);
}

include("host_details.inc");
include("version_func.inc");

if (isnull(port = get_app_port(cpe: CPE)))
  exit(0);

if (!infos = get_app_version_and_location(cpe: CPE, port: port, exit_no_version: TRUE))
  exit(0);

version = infos["version"];
location = infos["location"];

if (version_in_range_exclusive(version: version, test_version_lo: "4.0", test_version_up: "4.16.10")) {
  report = report_fixed_ver(installed_version: version, fixed_version: "4.16.10 / 4.17.7 / 4.18.1", install_path: location);
  security_message(port: port, data: report);
  exit(0);
}

if (version_in_range_exclusive(version: version, test_version_lo: "4.17.0", test_version_up: "4.17.7")) {
  report = report_fixed_ver(installed_version: version, fixed_version: "4.17.7 / 4.18.1", install_path: location);
  security_message(port: port, data: report);
  exit(0);
}

if (version_is_equal(version: version, test_version: "4.18.0")) {
  report = report_fixed_ver(installed_version: version, fixed_version: "4.18.1", install_path: location);
  security_message(port: port, data: report);
  exit(0);
}

exit(99);

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

59.9%