# CVE-2025-0620

## Summary

- **CVE ID:** CVE-2025-0620
- **Severity:** MEDIUM
- **CVSS Score:** 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-552
- **Published:** Jun 6, 2025
- **Last Modified:** Aug 31, 2026

## Description

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

## Affected Products

- Unknown product (4.21.0)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2025-0620)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2370453)
- [CNA](https://www.samba.org/samba/security/CVE-2025-0620.html)
- [CVE](http://www.openwall.com/lists/oss-security/2025/06/03/8)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.75%
- **EPSS Percentile:** 53.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._