CVE-2013-0214: Samba

Medium severity, CVSS 5.1. EPSS: 1.9% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.

Affected products

  • Samba Samba: version 3.6.0 only; version 3.6.1 only; version 3.6.2 only; version 3.6.3 only; version 3.6.4 only; version 3.6.5 only; …

Published 2013-02-02. Last modified 2026-06-16.