CVE-2018-16857
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing done to confirm an organisation's password policies apply as expected may not have been re-done after the upgrade.
Samba, desde la versión 4.9.0 y antes de la versión 4.9.3, con las configuraciones AD DC buscando malas contraseñas (para restringir la adivinación de contraseñas por fuerza bruta) durante más de 3 minutos podría no buscar malas contraseñas en absoluto. El riesgo principal de este problema está relacionado con los dominios que se han actualizado desde Samba 4.8 y anteriores. En estos casos, las pruebas manuales realizadas para confirmar que las políticas de contraseña de una organización se aplican como deberían podrían no volver a realizarse tras la actualización.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-09-11 CVE Reserved
- 2018-11-28 CVE Published
- 2024-05-30 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-358: Improperly Implemented Security Check for Standard
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106024 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16857 | Issue Tracking | |
https://security.netapp.com/advisory/ntap-20181127-0001 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.samba.org/samba/security/CVE-2018-16857.html | 2019-10-09 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202003-52 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | >= 4.9.0 < 4.9.3 Search vendor "Samba" for product "Samba" and version " >= 4.9.0 < 4.9.3" | - |
Affected
|