samba: SMB1 client connections can be downgraded to plaintext authentication
Published Feb 18, 2022
6.8
MEDIUMCVSS 3.1
EPSS 1.77%
Description
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
Affected products
- Vendor n/a Product Samba Defaultn/a
- Version samba 4.15.2, samba 4.14.10, samba 4.13.14StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Samba | n/a |
|
Configuration 1
Configuration 2
- 9.0
- 10.0
Configuration 3
- 33
- 34
- 35
Configuration 4
- n/a
- 3.0
- 3.5
- 13
- 16.1
- 16.2
- 4.0
- 7.0
- 8.0
- 7.0
- 8.2
- 8.4
- 7.0
- 8.0
- 8.2
- 8.4
- 7.0
- 7.0
- 8.0
- 8.2
- 8.4
- 7.0
- 7.0
- 7.0
- 8.2
- 8.4
- 8.4
- 8.2
- 8.4
- 8.2
- 7.0
Configuration 5
- 18.04
- 20.04
- 21.04
- 21.10
No data.
Red Hat Enterprise Linux 7
samba-0:4.10.16-17.el7_9
Fixed · RHSA-2021:5192
Red Hat Enterprise Linux 8
samba-0:4.14.5-7.el8_5
Fixed · RHSA-2021:5082
Red Hat Enterprise Linux 8
samba-0:4.14.5-7.el8_5
Fixed · RHSA-2021:5082
Red Hat Enterprise Linux 8.2 Extended Update Support
samba-0:4.11.2-18.el8_2
Fixed · RHSA-2022:0074
Red Hat Enterprise Linux 8.4 Extended Update Support
samba-0:4.13.3-8.el8_4
Fixed · RHSA-2022:0008
Red Hat Gluster Storage 3.5 for RHEL 7
samba-0:4.11.6-114.el7rhgs
Fixed · RHSA-2021:4844
Red Hat Gluster Storage 3.5 for RHEL 8
samba-0:4.14.5-204.el8rhgs
Fixed · RHSA-2021:4843
Red Hat Enterprise Linux 6
samba
Out of support scope
Red Hat Enterprise Linux 6
samba4
Out of support scope
Red Hat Enterprise Linux 9
samba
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | samba-0:4.10.16-17.el7_9 | Fixed | RHSA-2021:5192 |
| Red Hat Enterprise Linux 8 | samba-0:4.14.5-7.el8_5 | Fixed | RHSA-2021:5082 |
| Red Hat Enterprise Linux 8 | samba-0:4.14.5-7.el8_5 | Fixed | RHSA-2021:5082 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | samba-0:4.11.2-18.el8_2 | Fixed | RHSA-2022:0074 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | samba-0:4.13.3-8.el8_4 | Fixed | RHSA-2022:0008 |
| Red Hat Gluster Storage 3.5 for RHEL 7 | samba-0:4.11.6-114.el7rhgs | Fixed | RHSA-2021:4844 |
| Red Hat Gluster Storage 3.5 for RHEL 8 | samba-0:4.14.5-204.el8rhgs | Fixed | RHSA-2021:4843 |
| Red Hat Enterprise Linux 6 | samba | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | samba | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Ensure the following [global] smb.conf parameters are set to their default values as shown below: ~~~ client lanman auth = no client NTLMv2 auth = yes client plaintext auth = no client min protocol = SMB2_02 ~~~ Or use the '-k' command line option only without the -U option, which will make use of an existing krb5 ccache.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.77% (0.01766) | 77.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.72% (0.01718) | 74.40th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.57% (0.00571) | 66.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.33% (0.00325) | 71.63th | v3 (v2023.03.01) |
| May 12, 2024 | 0.19% (0.00194) | 56.65th | v3 (v2023.03.01) |
| Sep 17, 2023 | 0.14% (0.00136) | 48.55th | v3 (v2023.03.01) |
| Sep 15, 2023 | 0.19% (0.00189) | 56.00th | v3 (v2023.03.01) |
| Aug 1, 2023 | 0.13% (0.00132) | 47.42th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.12% (0.00123) | 44.92th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Sep 10, 2022 | 0.89% (0.00885) | 26.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 19, 2022 | 0.89% (0.00885) | 11.03th | v2 (v2022.01.01) |
References (7)
- https://access.redhat.com/security/cve/CVE-2016-2124 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2019660 Issue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2016-2124
- https://security.gentoo.org/glsa/202309-06 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-2124
- https://www.samba.org/samba/security/CVE-2016-2124.html MitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2016-2124 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2019660 | Issue TrackingPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html | mailing-list | |
| https://nvd.nist.gov/vuln/detail/CVE-2016-2124 | ||
| https://security.gentoo.org/glsa/202309-06 | vendor-advisory | |
| https://www.cve.org/CVERecord?id=CVE-2016-2124 | ||
| https://www.samba.org/samba/security/CVE-2016-2124.html | MitigationVendor Advisory |
Change history (0)
No recorded changes yet.