CVE-2017-12151 describes a flaw in Samba client versions prior to 4.4.16, 4.5.14, and 4.6.8, specifically when using SMB3 with DFS redirects. This vulnerability allows a man-in-the-middle attacker to bypass encryption and signing requirements, enabling them to read or alter sensitive data. Rated 7.4 HIGH, it presents a significant risk due to its network-based attack vector and high impact on confidentiality and integrity, despite requiring high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.4.16CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.5.0, < 4.5.14CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.6.0, < 4.6.8CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.