CVE-2016-2125
—CVSS 3.1
6.5 medium
EPSS
9%p95
Published
()
Modified
Description
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
In the news0 stories
No ingested article mentions this CVE yet.