CVE-2021-43566
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.
Todas las versiones de Samba anteriores a 4.13.16, son vulnerables a que un cliente malicioso use una carrera SMB1 o NFS para permitir la creación de un directorio en un área del sistema de archivos del servidor no exportada bajo la definición del recurso compartido. Tenga en cuenta que SMB1 tiene que estar habilitado, o el recurso compartido también disponible por medio de NFS para que este ataque tenga éxito
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-09 CVE Reserved
- 2022-01-11 CVE Published
- 2024-04-04 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20220110-0001 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://bugzilla.samba.org/show_bug.cgi?id=13979 | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://www.samba.org/samba/security/CVE-2021-43566.html | 2022-10-14 |
URL | Date | SRC |
---|