CVE-2011-2522
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.0%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 10.05% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- samba/samba · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://jvn.jp/en/jp/JVN29529126/index.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=133527864025056&w=2Mailing List, Third Party Advisory
- http://osvdb.org/74071Broken Link
- http://samba.org/samba/history/samba-3.5.10.htmlVendor Advisory
- http://secunia.com/advisories/45393Third Party Advisory
- http://secunia.com/advisories/45488Third Party Advisory
- http://secunia.com/advisories/45496Third Party Advisory
- http://securityreason.com/securityalert/8317Third Party Advisory
- http://securitytracker.com/id?1025852Third Party Advisory, VDB Entry
- http://ubuntu.com/usn/usn-1182-1Third Party Advisory
- http://www.debian.org/security/2011/dsa-2290Third Party Advisory
- http://www.exploit-db.com/exploits/17577Exploit, Third Party Advisory, VDB Entry
- http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:121Broken Link
- http://www.samba.org/samba/security/CVE-2011-2522Vendor Advisory
- http://www.securityfocus.com/bid/48899Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=721348Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=8290Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68843Third Party Advisory, VDB Entry
- http://jvn.jp/en/jp/JVN29529126/index.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=133527864025056&w=2Mailing List, Third Party Advisory
- http://osvdb.org/74071Broken Link
- http://samba.org/samba/history/samba-3.5.10.htmlVendor Advisory
- http://secunia.com/advisories/45393Third Party Advisory
- http://secunia.com/advisories/45488Third Party Advisory
- http://secunia.com/advisories/45496Third Party Advisory
- http://securityreason.com/securityalert/8317Third Party Advisory
- http://securitytracker.com/id?1025852Third Party Advisory, VDB Entry
- http://ubuntu.com/usn/usn-1182-1Third Party Advisory
- http://www.debian.org/security/2011/dsa-2290Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.