CVE-2016-2124 describes a flaw in Samba's SMB1 authentication, allowing an attacker to intercept plaintext passwords even when Kerberos was mandated. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high confidentiality impact, but requires high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 4.13.14CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.14.0, < 4.14.10CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.15.0, < 4.15.2CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2016-2124
Oct 8, 2024A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
Feb 8, 2022samba: SMB1 client connections can be downgraded to plaintext authentication
Nov 9, 2021