SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14318

An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

MEDIUM 4.3EPSS 1.54%

Does this matter?

Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.54% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-266, CWE-269
Affected
samba/samba · redhat/storage · redhat/enterprise linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.