Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16860

Опубликовано: 31 июл. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 6
EPSS Низкий

Описание

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
Версия от 4.8.0 (включая) до 4.8.12 (исключая)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
Версия от 4.9.0 (включая) до 4.9.8 (исключая)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
Версия от 4.10.0 (включая) до 4.10.3 (исключая)
Конфигурация 2
cpe:2.3:a:heimdal_project:heimdal:*:*:*:*:*:*:*:*
Версия от 0.8 (включая) до 7.5.0 (включая)

EPSS

Процентиль: 83%
0.01992
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-358
CWE-358

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

CVSS3: 7.5
redhat
больше 6 лет назад

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

CVSS3: 7.5
debian
около 6 лет назад

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x ...

CVSS3: 7.5
github
около 3 лет назад

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость реализации Heimdal протокола Kerberos пакета программ сетевого взаимодействия Samba, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

EPSS

Процентиль: 83%
0.01992
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-358
CWE-358