Vulnerability Name:

CVE-2022-0336 (CCN-218463)

Assigned:2022-01-31
Published:2022-01-31
Updated:2022-09-01
Summary:The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-276
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2022-0336

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://access.redhat.com/security/cve/CVE-2022-0336

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2046134

Source: MISC
Type: Issue Tracking, Patch, Vendor Advisory
https://bugzilla.samba.org/show_bug.cgi?id=14950

Source: XF
Type: UNKNOWN
samba-cve20220336-sec-bypass(218463)

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/samba-team/samba/commit/1a5dc817c0c9379bbaab14c676681b42b0039a3c

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/samba-team/samba/commit/c58ede44f382bd0125f761f0479c8d48156be400

Source: CCN
Type: Mend Vulnerability Database
CVE-2022-0336

Source: CCN
Type: Samba Web site
CVE-2022-0336.html

Source: MISC
Type: Vendor Advisory
https://www.samba.org/samba/security/CVE-2022-0336.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:samba:samba:*:*:*:*:*:*:*:* (Version >= 4.14.0 and < 4.14.12)
  • OR cpe:/a:samba:samba:*:*:*:*:*:*:*:* (Version >= 4.15.0 and < 4.15.4)
  • OR cpe:/a:samba:samba:*:*:*:*:*:*:*:* (Version >= 4.0.0 and < 4.13.17)

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:35:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:samba:samba:4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:samba:samba:4.13.0:-:*:*:*:*:*:*
  • OR cpe:/a:samba:samba:4.14.0:-:*:*:*:*:*:*
  • OR cpe:/a:samba:samba:4.15.0:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7662
    P
    libsamba-policy-devel-4.17.7+git.330.4057cd7a27a-150500.1.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3072
    P
    fuse-2.9.3-6.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94702
    P
    libsamba-policy-devel-4.15.5+git.328.f1f29505d84-150400.1.44 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:5339
    P
    Security update for samba (Critical)
    2022-02-14
    oval:org.opensuse.security:def:6156
    P
    Security update for samba (Critical)
    2022-02-14
    oval:org.opensuse.security:def:4303
    P
    Security update for samba (Critical)
    2022-02-14
    oval:org.opensuse.security:def:102146
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:99206
    P
    (Critical)
    2022-02-08
    oval:org.opensuse.security:def:1586
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:100410
    P
    (Critical)
    2022-02-08
    oval:org.opensuse.security:def:42332
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:102246
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:99480
    P
    (Critical)
    2022-02-08
    oval:org.opensuse.security:def:1685
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:100744
    P
    (Critical)
    2022-02-08
    oval:org.opensuse.security:def:102309
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:99742
    P
    (Critical)
    2022-02-08
    oval:org.opensuse.security:def:1757
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:101627
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:935
    P
    Security update for samba (Critical)
    2022-02-08
    oval:org.opensuse.security:def:100072
    P
    (Critical)
    2022-02-08
    BACK
    samba samba *
    samba samba *
    samba samba *
    fedoraproject fedora 34
    fedoraproject fedora 35
    samba samba 4.0.0
    samba samba 4.13.0 -
    samba samba 4.14.0
    samba samba 4.15.0 -