Key Information Vulnerability Description CVE Number: CVE-2020-25720 Public Disclosure Date: June 14, 2022 Last Updated: November 15, 2024 Affected Product: Samba Severity: Medium CVSS v3 Score: 7.5 Impact Affected Component: Samba Affected Versions: - Red Hat Enterprise Linux 6 - Red Hat Enterprise Linux 7 - Red Hat Enterprise Linux 8 - Red Hat Enterprise Linux 9 - Red Hat OpenShift Container Platform 4 - Red Hat Storage 3 Solution Mitigation: No available solution or current options do not meet Red Hat product security standards. CVSS v3 Analysis Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Detailed Analysis: - Attack Vector: Network - Attack Complexity: High - Privileges Required: Low - User Interaction: None - Scope: High - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High External References CVE-2020-25720 NVD Details Frequently Asked Questions Why does Red Hat’s CVSS v3 score or impact differ from other vendors? My product is listed as “under investigation” or “affected”—when will Red Hat release a fix? If my product is listed as “not fixed,” what should I do? What are mitigations? I have a Red Hat product, but it’s not listed above—am I affected? Why does my security scanner report this vulnerability on my product, even though my product version is fixed or unaffected? Additional Information Security Rating and Impact: Provided by Red Hat; may differ from NVD and other vendors’ ratings. Security Description Copyright: © 2021 Summary This vulnerability description provides detailed information about CVE-2020-25720, including its severity, affected components and versions, mitigation options, CVSS v3 score analysis, external references, and frequently asked questions.