CVE Vulnerabilities

CVE-2022-45141

Inadequate Encryption Strength

Published: Mar 06, 2023 | Modified: Sep 17, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Samba Samba * 4.15.13 (excluding)
Samba Samba 4.16.0 (including) 4.16.8 (excluding)
Samba Ubuntu bionic *
Samba Ubuntu esm-infra/bionic *
Samba Ubuntu focal *
Samba Ubuntu jammy *
Samba Ubuntu trusty *
Samba Ubuntu upstream *
Samba Ubuntu xenial *

Potential Mitigations

References