CVE-2022-2031

EUVD-2022-34335
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
sambasamba
𝑥
< 4.14.14
sambasamba
4.15.0 ≤
𝑥
< 4.15.9
sambasamba
4.16.0 ≤
𝑥
< 4.16.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
samba
bookworm
2:4.17.12+dfsg-0+deb12u1
fixed
bookworm (security)
2:4.17.12+dfsg-0+deb12u1
fixed
bullseye
2:4.13.13+dfsg-1~deb11u6
fixed
bullseye (security)
2:4.13.13+dfsg-1~deb11u6
fixed
buster
ignored
sid
2:4.21.1+dfsg-2
fixed
trixie
2:4.21.1+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
bionic
ignored
focal
Fixed 2:4.13.17~dfsg-0ubuntu1.20.04.1
released
impish
ignored
jammy
Fixed 2:4.15.9+dfsg-0ubuntu0.2
released
kinetic
Fixed 2:4.16.4+dfsg-2ubuntu1
released
lunar
Fixed 2:4.16.4+dfsg-2ubuntu1
released
mantic
Fixed 2:4.16.4+dfsg-2ubuntu1
released
noble
Fixed 2:4.16.4+dfsg-2ubuntu1
released
trusty
needed
xenial
needed