{"api_version":"1","generated_at":"2026-07-24T18:22:16+00:00","cve":"CVE-2018-1057","urls":{"html":"https://cve.report/CVE-2018-1057","api":"https://cve.report/api/cve/CVE-2018-1057.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-1057","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-1057"},"summary":{"title":"CVE-2018-1057","description":"On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-03-13 16:29:00","updated_at":"2022-08-29 20:11:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"https://usn.ubuntu.com/3595-1/","name":"USN-3595-1","refsource":"UBUNTU","tags":["Third Party Advisory"],"title":"USN-3595-1: Samba vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/103382","name":"103382","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Samba CVE-2018-1057 Remote Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.synology.com/support/security/Synology_SA_18_08","name":"https://www.synology.com/support/security/Synology_SA_18_08","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Synology Inc.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html","name":"[debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] [DLA 1754-1] samba security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.netapp.com/advisory/ntap-20180313-0001/","name":"https://security.netapp.com/advisory/ntap-20180313-0001/","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"March 2018 Samba Vulnerabilities in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1040494","name":"1040494","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Samba Active Directory Domain Controller LDAP Permissions Error Lets Remote Authenticated Users Modify User Passwords on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201805-07","name":"GLSA-201805-07","refsource":"GENTOO","tags":["Third Party Advisory"],"title":"Samba: Multiple vulnerabilities  (GLSA 201805-07) — Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1553553","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1553553","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1553553 – (CVE-2018-1057) CVE-2018-1057 samba: Authenticated users can change other users password in an AD DC configuration","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2018/dsa-4135","name":"DSA-4135","refsource":"DEBIAN","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-4135-1 samba","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.samba.org/samba/security/CVE-2018-1057.html","name":"https://www.samba.org/samba/security/CVE-2018-1057.html","refsource":"CONFIRM","tags":["Mitigation","Vendor Advisory"],"title":"Samba - Security Announcement Archive","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-1057","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1057","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"14.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"16.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"17.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"14.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"16.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"17.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samba","cpe5":"samba","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1057","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samba","cpe5":"samba","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2018-1057","qid":"500634","title":"Alpine Linux Security Update for samba"},{"cve":"CVE-2018-1057","qid":"504398","title":"Alpine Linux Security Update for samba"},{"cve":"CVE-2018-1057","qid":"690260","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for samba (fb26f78a-26a9-11e8-a1c2-00505689d4ae)"},{"cve":"CVE-2018-1057","qid":"901071","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for samba (7346)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2018-1057","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-863","cweId":"CWE-863"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Samba","product":{"product_data":[{"product_name":"Samba","version":{"version_data":[{"version_affected":"=","version_value":"All versions of Samba from 4.0.0 onwards."}]}}]}}]}},"references":{"reference_data":[{"url":"http://www.securityfocus.com/bid/103382","refsource":"MISC","name":"http://www.securityfocus.com/bid/103382"},{"url":"http://www.securitytracker.com/id/1040494","refsource":"MISC","name":"http://www.securitytracker.com/id/1040494"},{"url":"https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html","refsource":"MISC","name":"https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html"},{"url":"https://security.gentoo.org/glsa/201805-07","refsource":"MISC","name":"https://security.gentoo.org/glsa/201805-07"},{"url":"https://security.netapp.com/advisory/ntap-20180313-0001/","refsource":"MISC","name":"https://security.netapp.com/advisory/ntap-20180313-0001/"},{"url":"https://usn.ubuntu.com/3595-1/","refsource":"MISC","name":"https://usn.ubuntu.com/3595-1/"},{"url":"https://www.debian.org/security/2018/dsa-4135","refsource":"MISC","name":"https://www.debian.org/security/2018/dsa-4135"},{"url":"https://www.samba.org/samba/security/CVE-2018-1057.html","refsource":"MISC","name":"https://www.samba.org/samba/security/CVE-2018-1057.html"},{"url":"https://www.synology.com/support/security/Synology_SA_18_08","refsource":"MISC","name":"https://www.synology.com/support/security/Synology_SA_18_08"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1553553","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1553553"}]}},"nvd":{"publishedDate":"2018-03-13 16:29:00","lastModifiedDate":"2022-08-29 20:11:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:lts:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"4.7.0","versionEndExcluding":"4.7.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6.0","versionEndExcluding":"4.6.14","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.5.16","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"1057","Ordinal":"116288","Title":"CVE-2018-1057","CVE":"CVE-2018-1057","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"1057","Ordinal":"1","NoteData":"On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).","Type":"Description","Title":null},{"CveYear":"2018","CveId":"1057","Ordinal":"2","NoteData":"2018-03-13","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"1057","Ordinal":"3","NoteData":"2019-04-09","Type":"Other","Title":"Modified"}]}}}