VulnerabilityModified
CVE-2016-2124
An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
MEDIUM 5.9EPSS 1.75%
Does this matter?
Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- samba/samba · debian/debian linux · fedoraproject/fedora · redhat/codeready linux builder · redhat/gluster storage · redhat/openstack · redhat/virtualization host · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power big endian · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux for scientific computing · redhat/enterprise linux resilient storage · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · +4 more
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2019660Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html
- https://security.gentoo.org/glsa/202309-06
- https://www.samba.org/samba/security/CVE-2016-2124.htmlMitigation, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2019660Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html
- https://security.gentoo.org/glsa/202309-06
- https://www.samba.org/samba/security/CVE-2016-2124.htmlMitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.