Vulnerability Details CVE-2001-0981
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.3%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2001-0981
-
cpe:2.3:a:hp:cifs-9000_server:-
-
cpe:2.3:a:hp:cifs-9000_server:a.01.05
-
cpe:2.3:a:hp:cifs-9000_server:a.01.06
-
cpe:2.3:a:hp:cifs-9000_server:a.01.07