Sales Chat - Click Here

Kerberos sets the forwardable flag even if the impersonated client has the not-delegated flag set


Jun 23, 2023

Kerberos sets the forwardable flag even if the impersonated client has the not-delegated flag set

Summary

This vulnerability applies to functionality when the system is acting as an Active Directory domain controller. No Buffalo NAS products use this functionality, and so no Buffalo sytems are affected by this vulnerability.

Vulnerability ID Vulnerability Overview
CVE-2019-14870 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

Affected Supported TeraStations

None

Back to Security Notices

Date Description
6/23/2022 Initial release
X