CVE-2017-12151
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 7.66%
- CWE
- CWE-300
- Published
- 2018-07-27
- Last modified
- 2026-03-14
Affected products
- Samba samba
- Samba samba
- Samba samba
Weakness type
Related vulnerabilities
- CVE-2025-54792 — LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
- CVE-2017-12150 — It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when ce
- CVE-2023-31004 — IBM Security Access Manager Container gain access
- CVE-2024-31206 — Use of Unencrypted HTTP Request in dectalk-tts
- CVE-2019-3793 — Invitations Service supports HTTP connections
- CVE-2025-20122 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2023-32634 — An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant