Risk Scores
CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
85.89%
99.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.18.6-101.el9_3, 0:4.18.6-101.el9_3 |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 0:4.15.5-13.el8_6 |
| Red Hat | Red Hat Storage 3 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.18.6-2.el8_9, 0:4.18.6-2.el8_9 |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | 0:4.15.5-13.el8_6 |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:4.15.5-111.el9_0 |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:4.17.5-104.el9_2 |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | 0:4.17.5-4.el8_8 |
Timeline
- Jun 9, 2023 PoC Published
- Jul 15, 2023 PoC Published
- Nov 4, 2023 PoC Published
- Dec 8, 2023 PoC Published
- Dec 8, 2023 CVE Published
- Dec 9, 2023 EPSS Score
- Dec 21, 2023 CISA KEV Added
- Jan 7, 2024 EPSS Score
- Mar 1, 2024 PoC Published
- Mar 4, 2024 EPSS Score
- Apr 2, 2024 EPSS Score
- Apr 5, 2024 PoC Published
References
- https://www.qnap.com/fr-fr/security-advisory/qsa-23-07 advisory
- https://www.qnap.com/fr-fr/security-advisory/qsa-23-40 advisory
- https://www.qnap.com/fr-fr/security-advisory/qsa-23-48 advisory
- https://www.qnap.com/fr-fr/security-advisory/qsa-23-20 advisory
- RHSA-2023:6209 vendor-advisory
- RHSA-2023:6744 vendor-advisory
- RHSA-2023:7371 vendor-advisory
- RHSA-2023:7408 vendor-advisory
- RHSA-2023:7464 vendor-advisory
- RHSA-2023:7467 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-4091 vdb
- RHBZ#2241882 issue
- https://bugzilla.samba.org/show_bug.cgi?id=15439 url
- https://www.samba.org/samba/security/CVE-2023-4091.html url
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZUMVALLFFDFC53JZMUWA6HPD7HUGAP5I/ url
- https://security.netapp.com/advisory/ntap-20231124-0002/ url