CVE-2017-12151Channel Accessible by Non-Endpoint in Samba

Severity
7.4HIGHNVD
EPSS
4.1%
top 11.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 13

Description

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages8 packages

NVDsamba/samba4.5.04.5.14+2
Debiansamba/samba< 2:4.6.7+dfsg-2+3
Ubuntusamba/samba< 2:4.3.11+dfsg-0ubuntu0.14.04.12+1
CVEListV5samba/samba4.4.16, 4.5.14, 4.6.8+2
NVDhp/cifs_serverb.04.05.11.00

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.0, 7.4, 7.5

🔴Vulnerability Details

4
GHSA
GHSA-xc7p-hf9j-w53w: A flaw was found in the way samba client before samba 42022-05-13
CVEList
CVE-2017-12151: A flaw was found in the way samba client before samba 42018-07-27
OSV
CVE-2017-12151: A flaw was found in the way samba client before samba 42018-07-27
OSV
samba vulnerabilities2017-09-21

📋Vendor Advisories

4
Red Hat
samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)2017-10-24
Ubuntu
Samba vulnerabilities2017-09-21
Red Hat
samba: SMB2 connections don't keep encryption across DFS redirects2017-09-20
Debian
CVE-2017-12151: samba - A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and s...2017

💬Community

3
Bugzilla
CVE-2017-15086 samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)2017-10-24
Bugzilla
CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]2017-09-20
Bugzilla
CVE-2017-12151 samba: SMB2 connections don't keep encryption across DFS redirects2017-09-04
CVE-2017-12151 — Channel Accessible by Non-Endpoint | cvebase