The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://www.samba.org/samba/security/CVE-2023-0922.html | mitigation vendor advisory |
https://security.netapp.com/advisory/ntap-20230406-0007/ | third party advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXBPYIA4VWNOD437NAHZ3NXKAETLFB5S/ | vendor advisory |
https://security.gentoo.org/glsa/202309-06 | vendor advisory |