CVE-2000-0937 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.7% (pctl 94)
Patch early
A public exploit exists.
Description
Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.74% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-12-19 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| samba | samba |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Samba 2.0.7 - SWAT Logging Failure | 2000-11-01 |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html
- http://www.securityfocus.com/bid/1873
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5442
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html
- http://www.securityfocus.com/bid/1873
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5442
→ the Explorer · watch your stack · NVD