{"api_version":"1","generated_at":"2026-04-23T02:35:10+00:00","cve":"CVE-2018-16860","urls":{"html":"https://cve.report/CVE-2018-16860","api":"https://cve.report/api/cve/CVE-2018-16860.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-16860","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860"},"summary":{"title":"CVE-2018-16860","description":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-07-31 15:15:00","updated_at":"2019-08-14 12:15:00"},"problem_types":["CWE-358"],"metrics":[],"references":[{"url":"http://seclists.org/fulldisclosure/2019/Aug/13","name":"20190816 APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 12.4","refsource":"FULLDISC","tags":[],"title":"Full Disclosure: APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 12.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2019/Aug/14","name":"20190816 APPLE-SA-2019-8-13-3 Additional information for APPLE-SA-2019-7-22-4 watchOS 5.3","refsource":"FULLDISC","tags":[],"title":"Full Disclosure: APPLE-SA-2019-8-13-3 Additional information for APPLE-SA-2019-7-22-4 watchOS 5.3","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.synology.com/security/advisory/Synology_SA_19_23","name":"https://www.synology.com/security/advisory/Synology_SA_19_23","refsource":"CONFIRM","tags":[],"title":"Synology Inc.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT210348","name":"https://support.apple.com/HT210348","refsource":"CONFIRM","tags":[],"title":"About the security content of macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT210346","name":"https://support.apple.com/HT210346","refsource":"CONFIRM","tags":[],"title":"About the security content of iOS 12.4 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1705877 – (CVE-2018-16860) CVE-2018-16860 samba: S4U2Self with unkeyed checksum","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Aug/21","name":"20190814 APPLE-SA-2019-8-13-1 Additional information for APPLE-SA-2019-7-22-2 macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: APPLE-SA-2019-8-13-1 Additional information for APPLE-SA-2019-7-22-2 macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2019/Aug/15","name":"20190816 APPLE-SA-2019-8-13-4 Additional information for APPLE-SA-2019-7-22-5 tvOS 12.4","refsource":"FULLDISC","tags":[],"title":"Full Disclosure: APPLE-SA-2019-8-13-4 Additional information for APPLE-SA-2019-7-22-5 tvOS 12.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT210353","name":"https://support.apple.com/HT210353","refsource":"CONFIRM","tags":[],"title":"About the security content of watchOS 5.3 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Aug/25","name":"20190814 APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 12.4","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 12.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.samba.org/samba/security/CVE-2018-16860.html","name":"https://www.samba.org/samba/security/CVE-2018-16860.html","refsource":"MISC","tags":["Mitigation","Vendor Advisory"],"title":"Samba - Security Announcement Archive","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2019/Aug/11","name":"20190816 APPLE-SA-2019-8-13-1 Additional information for APPLE-SA-2019-7-22-2 macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra","refsource":"FULLDISC","tags":[],"title":"Full Disclosure: APPLE-SA-2019-8-13-1 Additional information for APPLE-SA-2019-7-22-2 macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Aug/23","name":"20190814 APPLE-SA-2019-8-13-4 Additional information for APPLE-SA-2019-7-22-5 tvOS 12.4","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: APPLE-SA-2019-8-13-4 Additional information for APPLE-SA-2019-7-22-5 tvOS 12.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT210351","name":"https://support.apple.com/HT210351","refsource":"CONFIRM","tags":[],"title":"About the security content of tvOS 12.4 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202003-52","name":"GLSA-202003-52","refsource":"GENTOO","tags":[],"title":"Samba: Multiple vulnerabilities (GLSA 202003-52) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Aug/22","name":"20190814 APPLE-SA-2019-8-13-3 Additional information for APPLE-SA-2019-7-22-4 watchOS 5.3","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: APPLE-SA-2019-8-13-3 Additional information for APPLE-SA-2019-7-22-4 watchOS 5.3","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html","name":"openSUSE-SU-2019:1888","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2019:1888-1: moderate: Security update f","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-16860","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16860","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"16860","vulnerable":"1","versionEndIncluding":"7.5.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"heimdal_project","cpe5":"heimdal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"16860","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samba","cpe5":"samba","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"16860","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samba","cpe5":"samba","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2018-16860","qid":"198986","title":"Ubuntu Security Notification for Heimdal Vulnerabilities (USN-5675-1)"},{"cve":"CVE-2018-16860","qid":"500245","title":"Alpine Linux Security Update for heimdal"},{"cve":"CVE-2018-16860","qid":"500619","title":"Alpine Linux Security Update for samba"},{"cve":"CVE-2018-16860","qid":"503993","title":"Alpine Linux Security Update for heimdal"},{"cve":"CVE-2018-16860","qid":"504381","title":"Alpine Linux Security Update for samba"},{"cve":"CVE-2018-16860","qid":"670882","title":"EulerOS Security Update for samba (EulerOS-SA-2020-2396)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2018-16860","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"SAMBA","product":{"product_data":[{"product_name":"samba","version":{"version_data":[{"version_value":"4.8.x up to, excluding 4.8.12"},{"version_value":"4.9.x up to, excluding 4.9.8"},{"version_value":"4.10.x up to, excluding 4.10.3"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-358"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://www.synology.com/security/advisory/Synology_SA_19_23","url":"https://www.synology.com/security/advisory/Synology_SA_19_23"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16860","refsource":"CONFIRM"},{"url":"https://www.samba.org/samba/security/CVE-2018-16860.html","refsource":"MISC","name":"https://www.samba.org/samba/security/CVE-2018-16860.html"},{"refsource":"BUGTRAQ","name":"20190814 APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 12.4","url":"https://seclists.org/bugtraq/2019/Aug/25"},{"refsource":"BUGTRAQ","name":"20190814 APPLE-SA-2019-8-13-3 Additional information for APPLE-SA-2019-7-22-4 watchOS 5.3","url":"https://seclists.org/bugtraq/2019/Aug/22"},{"refsource":"BUGTRAQ","name":"20190814 APPLE-SA-2019-8-13-4 Additional information for APPLE-SA-2019-7-22-5 tvOS 12.4","url":"https://seclists.org/bugtraq/2019/Aug/23"},{"refsource":"BUGTRAQ","name":"20190814 APPLE-SA-2019-8-13-1 Additional information for APPLE-SA-2019-7-22-2 macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra","url":"https://seclists.org/bugtraq/2019/Aug/21"},{"refsource":"SUSE","name":"openSUSE-SU-2019:1888","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00026.html"},{"refsource":"FULLDISC","name":"20190816 APPLE-SA-2019-8-13-3 Additional information for APPLE-SA-2019-7-22-4 watchOS 5.3","url":"http://seclists.org/fulldisclosure/2019/Aug/14"},{"refsource":"FULLDISC","name":"20190816 APPLE-SA-2019-8-13-1 Additional information for APPLE-SA-2019-7-22-2 macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra","url":"http://seclists.org/fulldisclosure/2019/Aug/11"},{"refsource":"FULLDISC","name":"20190816 APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 12.4","url":"http://seclists.org/fulldisclosure/2019/Aug/13"},{"refsource":"FULLDISC","name":"20190816 APPLE-SA-2019-8-13-4 Additional information for APPLE-SA-2019-7-22-5 tvOS 12.4","url":"http://seclists.org/fulldisclosure/2019/Aug/15"},{"refsource":"CONFIRM","name":"https://support.apple.com/HT210346","url":"https://support.apple.com/HT210346"},{"refsource":"CONFIRM","name":"https://support.apple.com/HT210348","url":"https://support.apple.com/HT210348"},{"refsource":"CONFIRM","name":"https://support.apple.com/HT210351","url":"https://support.apple.com/HT210351"},{"refsource":"CONFIRM","name":"https://support.apple.com/HT210353","url":"https://support.apple.com/HT210353"},{"refsource":"GENTOO","name":"GLSA-202003-52","url":"https://security.gentoo.org/glsa/202003-52"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal."}]},"impact":{"cvss":[[{"vectorString":"7.5/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.0"}]]}},"nvd":{"publishedDate":"2019-07-31 15:15:00","lastModifiedDate":"2019-08-14 12:15:00","problem_types":["CWE-358"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6},"severity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10.0","versionEndExcluding":"4.10.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8.0","versionEndExcluding":"4.8.12","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.0","versionEndExcluding":"4.9.8","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:heimdal_project:heimdal:*:*:*:*:*:*:*:*","versionStartIncluding":"0.8","versionEndIncluding":"7.5.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"16860","Ordinal":"133671","Title":"CVE-2018-16860","CVE":"CVE-2018-16860","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"16860","Ordinal":"1","NoteData":"A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"16860","Ordinal":"2","NoteData":"2019-07-31","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"16860","Ordinal":"3","NoteData":"2020-03-25","Type":"Other","Title":"Modified"}]}}}