The Samba Team has released security updates to address vulnerabilities in multiple versions of Samba.
CVE-2022-38023 allow remote authenticated users to bypass security constraint and conduct attacks via a susceptible version of ADM with SMB service enabled.
The best solution for CVE-2022-37966 should be applied on the AD Server, please refer to Mitigation for details.
CVE-2022-37967 and CVE-2022-45141 will not affect current ASUSTOR products as this vulnerability only affect AD DC features that ADM didn't support.
Samba package has been updated on ADM 4.0.6.RCR1 to fix these potential vulnerabilities.
• CVE-2022-32742, CVE-2022-2031, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746. (AS-2022-014)
• CVE-2022-3437, CVE-2022-42898. (AS-2022-016) |