01642 06 11 11 Arrange Call

Samba DCE/RPC Fragmentation Vulnerability

CVE-2021-23192 · HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVE-2021-23192

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

Learn more about our Cis Benchmark Audit For Server Software.