CVE-2011-2522 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities within the Samba Web Administration Tool (SWAT) in Samba 3.x versions prior to 3.5.10, impacting various Linux distributions. These flaws allow remote attackers to hijack authenticated administrator sessions to perform critical actions like managing daemons, shares, printers, and user accounts. The vulnerability has a CVSS score of 6.8 (Medium), indicating a network-based attack with medium complexity, potentially leading to partial confidentiality, integrity, and availability impacts. Its FAUCET Risk Score of 95/100 highlights its significant potential for misuse. While not listed on the CISA KEV catalog or actively exploited, exploit code is publicly available via ExploitDB (EDB-17577). Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.3.16CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.14CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 3.5.0, < 3.5.10CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.