CVE-2017-12150 describes a vulnerability in Samba versions before 4.4.16, 4.5.14, and 4.6.8, where SMB signing was not enforced even when configured, affecting Debian, Red Hat, and Samba products. This flaw allows a remote attacker to conduct a man-in-the-middle attack with high complexity (AC:H) to retrieve sensitive information in plaintext, resulting in a CVSS score of 7.4 (High) for confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.25, < 4.4.16CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.5.0, < 4.5.14CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.6.0, < 4.6.8CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2017-12150
Oct 8, 2024It was found that samba before 4.4.16 4.5.x before 4.5.14 and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.
Jul 10, 2018samba: Some code path don't enforce smb signing, when they should
Sep 20, 2017