CVE-2021-3670

MEDIUM

Samba 4.1.0-4.15.9 - Uncontrolled Resource Consumption via MaxQueryDuration LDAP Bypass

Title source: llm
STIX 2.1

Description

MaxQueryDuration not honoured in Samba AD DC LDAP

Scores

CVSS v3 6.5
EPSS 0.0343
EPSS Percentile 87.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (3)
fedoraproject/fedora 35
redhat/storage 3.0
samba/samba 4.1.0 - 4.16.0
Published Aug 23, 2022
Tracked Since Feb 18, 2026