CVE-2023-0614

MEDIUM

Samba < 4.16.10 - Information Disclosure

Title source: rule

Description

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 47.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200 CWE-312
Status published

Affected Products (6)

samba/samba < 4.16.10
samba/samba
samba/samba
samba/samba
samba/samba
samba/samba

Timeline

Published Apr 03, 2023
Tracked Since Feb 18, 2026