AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2022-3437

MEDIUM · CVSS 6.5 EPSS 3.69%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-12 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2022-3437
Severity
MEDIUM
CVSS
6.5
EPSS
3.69%

Original NVD Description

A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack.

Related CVEs

Other vulnerabilities affecting the same vendor(s)