SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-2124

An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.

MEDIUM 5.9EPSS 1.75%

Does this matter?

Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.75% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
samba/samba · debian/debian linux · fedoraproject/fedora · redhat/codeready linux builder · redhat/gluster storage · redhat/openstack · redhat/virtualization host · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power big endian · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux for scientific computing · redhat/enterprise linux resilient storage · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · +4 more
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.