Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26200
HistoryAug 06, 2020 - 9:35 p.m.

Dictionary Attacks

2020-08-0621:35:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.001 Low

EPSS

Percentile

47.2%

samba is vulnerable to dictionary attacks. The vulnerability exists in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it vulnerable to dictionary attacks.