PT-2016-3366 · Samba+9 · Samba+9

Huzaifa S. Sidhpurwala

·

Published

2016-11-24

·

Updated

2024-06-15

·

CVE-2016-2124

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions prior to the fixed version
Description A flaw was found in the way Samba implemented SMB1 authentication, allowing an attacker to retrieve the plaintext password sent over the wire, even if Kerberos authentication was required. This could enable a remote attacker to perform a man-in-the-middle attack.
Recommendations For versions prior to the fixed version, consider disabling SMB1 authentication until a patch is available. As a temporary workaround, restrict the use of plaintext passwords in SMB1 connections to minimize the risk of exploitation. Avoid using SMB1 for authentication whenever possible, and opt for more secure authentication methods like Kerberos. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:5082
ALT-PU-2021-3247
ALT-PU-2021-3296
ALT-PU-2021-3339
ALT-PU-2021-3470
AZL-36986
AZL-8649
BDU:2021-05993
CESA-2021_5082
CESA-2021_5192
CVE-2016-2124
DLA-3563-1
DSA-5003-1
ECHO-E919-1845-5DB0
MGASA-2021-0585
OESA-2021-1461
OPENSUSE-SU-2021:1471-1
OPENSUSE-SU-2021:3647-1
OPENSUSE-SU-2021:3650-1
OPENSUSE-SU-2021:3674-1
OPENSUSE-SU-2021_1471-1
OPENSUSE-SU-2021_3647-1
OPENSUSE-SU-2021_3650-1
OPENSUSE-SU-2021_3674-1
OPENSUSE-SU-2024:11631-1
RHSA-2021:4843
RHSA-2021:4844
RHSA-2021:5082
RHSA-2021:5192
RHSA-2021_5082
RHSA-2021_5192
RHSA-2022:0008
RHSA-2022:0074
RLSA-2021:5082
SUSE-SU-2021:3647-1
SUSE-SU-2021:3649-1
SUSE-SU-2021:3650-1
SUSE-SU-2021:3673-1
SUSE-SU-2021:3674-1
SUSE-SU-2021:3746-1
SUSE-SU-2021:3747-1
SUSE-SU-2021_3647-1
SUSE-SU-2021_3649-1
SUSE-SU-2021_3650-1
SUSE-SU-2021_3673-1
SUSE-SU-2021_3674-1
SUSE-SU-2021_3746-1
SUSE-SU-2021_3747-1
SUSE-SU-2022:0361-1
USN-5142-1
USN-5142-2
USN-5142-3
USN-5174-1
USN-5174-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Samba
Suse
Ubuntu