CVE-2010-0833
Last modified
CVE-2010-0833 is a vulnerability of currently unknown severity. The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.. EPSS estimates a 4.14% chance of exploitation in the next 30 days.
Description
The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Likewise | Likewise Open | 5.4 |
| Likewise | Likewise Open | 6.0 |
| Likewise | Likewise Cifs | 5.4 |
References
- http://secunia.com/advisories/40725Vendor Advisory
- http://secunia.com/advisories/40736Vendor Advisory
- http://secunia.com/advisories/43244Vendor Advisory
- http://www.likewise.com/community/index.php/forums/viewthread/772/Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1913Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0312Vendor Advisory
- http://secunia.com/advisories/40725Vendor Advisory
- http://secunia.com/advisories/40736Vendor Advisory
- http://secunia.com/advisories/43244Vendor Advisory
- http://www.likewise.com/community/index.php/forums/viewthread/772/Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1913Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0312Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0833?
How severe is CVE-2010-0833?
How do I fix CVE-2010-0833?
Are you affected by CVE-2010-0833?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
