CVE-2017-12150Channel Accessible by Non-Endpoint in Samba

Severity
7.4HIGHNVD
EPSS
19.9%
top 4.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 13

Description

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages9 packages

NVDsamba/samba3.0.254.4.16+2
Debiansamba/samba< 2:4.6.7+dfsg-2+3
Ubuntusamba/samba< 2:4.3.11+dfsg-0ubuntu0.14.04.12+1
CVEListV5samba/samba4 versions+3

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-3747-3v6r-p947: It was found that samba before 42022-05-13
OSV
CVE-2017-12150: It was found that samba before 42018-07-26
CVEList
CVE-2017-12150: It was found that samba before 42018-07-26
OSV
samba vulnerabilities2017-09-21

📋Vendor Advisories

6
Microsoft
It was found that samba before 4.4.16 4.5.x before 4.5.14 and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-2018-07-10
Ubuntu
Samba vulnerabilities2017-11-02
Red Hat
samba: Some code path don't enforce smb signing, when they should (incomplete fix of CVE-2017-12150)2017-10-24
Ubuntu
Samba vulnerabilities2017-09-21
Red Hat
samba: Some code path don't enforce smb signing, when they should2017-09-20

💬Community

3
Bugzilla
CVE-2017-15085 samba: Some code path don't enforce smb signing, when they should (incomplete fix of CVE-2017-12150)2017-10-24
Bugzilla
CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]2017-09-20
Bugzilla
CVE-2017-12150 samba: Some code path don't enforce smb signing, when they should2017-09-05
CVE-2017-12150 — Channel Accessible by Non-Endpoint | cvebase