VulnerabilityModified
CVE-2017-12150
A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.
HIGH 7.4EPSS 13.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.
- CVSS 3.1
- 7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 13.33% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-300
- Affected
- samba/samba · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · redhat/gluster storage · debian/debian linux
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/100918Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039401Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2789Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2790Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2791Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2858Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12150Issue Tracking, Mitigation, Third Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_usThird Party Advisory
- https://security.netapp.com/advisory/ntap-20170921-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_usThird Party Advisory
- https://www.debian.org/security/2017/dsa-3983Third Party Advisory
- https://www.samba.org/samba/security/CVE-2017-12150.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/100918Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039401Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2789Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2790Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2791Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2858Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12150Issue Tracking, Mitigation, Third Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_usThird Party Advisory
- https://security.netapp.com/advisory/ntap-20170921-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_usThird Party Advisory
- https://www.debian.org/security/2017/dsa-3983Third Party Advisory
- https://www.samba.org/samba/security/CVE-2017-12150.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.