yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-0922
Component Overview
Vulnerability Overview
Name
CVE-2023-0922
Source
NVD (
link
)
Debian (
link
)
Description
The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.
CWEs
CWE-319
CWE-319
Published Date
Apr 3, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://security.netapp.com/advisory/ntap-20230406-0007/
Third Party Advisory
https://www.samba.org/samba/security/CVE-2023-0922.html
Mitigation
https://security.netapp.com/advisory/ntap-20230406-0007/
Third Party Advisory
https://www.samba.org/samba/security/CVE-2023-0922.html
Mitigation
Analysis
#
Affected Component
Analysis
samba
Patched
Vulnerability Ratings
#
5.9
CVSSv31
5.9
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
samba4
buildroot
2025.02.x
4.22.10
Not Affected
samba4
buildroot
master
4.24.3
Not Affected
samba4
openwrt
master
4.22.7-r3
Not Affected
samba4
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
samba
yocto
master
4.23.5
Not Affected
samba
yocto
scarthgap
4.19.9
Not Affected
Resolved with patches
#
samba (yocto:kirkstone)
#
Title
Author
Resolve
1
CVE-2023-0922 set default ldap client sasl wrapping to seal
Rob van der Linde <rob@catalyst.net.nz>
CVE-2023-0922