CVE-2016-2124
Severity
5.9MEDIUM
EPSS
0.7%
top 28.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 18
Latest updateFeb 19
Description
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6
Affected Packages11 packages
Also affects: Debian Linux 10.0, 9.0, Fedora 33, 34, 35, Ubuntu Linux 18.04, 20.04, 21.04, 21.10, Enterprise Linux 7.0, 8.0, 8.2, 8.4
Patches
🔴Vulnerability Details
8GHSA
▶
📋Vendor Advisories
5Microsoft▶
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.↗2022-02-08
Debian▶
CVE-2016-2124: samba - A flaw was found in the way samba implemented SMB1 authentication. An attacker c...↗2016