SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-0833

The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service,…

HIGH 9.3EPSS 4.14%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
4.14% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
likewise/likewise open · likewise/likewise cifs
Source
security@ubuntu.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.