Race Condition Vulnerability in Samba Password Lockout Mechanism
CVE-2021-20251

5.9MEDIUM

Key Information:

Vendor

Samba

Status
Vendor
CVE Published:
6 March 2023

What is CVE-2021-20251?

A flaw exists within the Samba software that introduces a race condition in the password lockout process. When specific conditions occur, this flaw can potentially allow attackers to execute successful brute force attacks despite the implemented lockout measures, compromising the security of user accounts.

Affected Version(s)

samba Samba 4.1 and newer

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.