7.5

CVE-2016-2118

The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "BADLOCK."

Data is provided by the National Vulnerability Database (NVD)
SambaSamba Version >= 3.6.0 < 4.2.10
SambaSamba Version >= 4.3.0 < 4.3.7
SambaSamba Version >= 4.4.0 < 4.4.1
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version15.10
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionlts
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 78.65% 0.99
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
http://badlock.org/
Third Party Advisory
Technical Description
https://www.kb.cert.org/vuls/id/813296
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/86002
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1035533
Third Party Advisory
VDB Entry