samba: SMB2 connections don't keep encryption across DFS redirects
Published Jul 27, 2018
7.4
HIGHCVSS 3.0
EPSS 4.59%
Description
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
Affected products
-
- Version 4.4.16StatusaffectedConstraints-
- Version 4.5.14StatusaffectedConstraints-
- Version 4.6.8StatusaffectedConstraints-
- Version
Configuration 1
Configuration 2
- 8.0
- 9.0
- 7.0
- 7.0
- 7.4
- 7.4
- 7.5
- 7.0
Configuration 3
- b.04.05.11.00
No data.
Red Hat Enterprise Linux 7
samba-0:4.6.2-11.el7_4
Fixed · RHSA-2017:2790
Red Hat Gluster Storage 3.3 for RHEL 6
samba-0:4.6.3-6.el6rhs
Fixed · RHSA-2017:2858
Red Hat Gluster Storage 3.3 for RHEL 7
samba-0:4.6.3-6.el7rhgs
Fixed · RHSA-2017:2858
Red Hat Enterprise Linux 5
samba
Not affected
Red Hat Enterprise Linux 5
samba3x
Not affected
Red Hat Enterprise Linux 6
samba
Not affected
Red Hat Enterprise Linux 6
samba4
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | samba-0:4.6.2-11.el7_4 | Fixed | RHSA-2017:2790 |
| Red Hat Gluster Storage 3.3 for RHEL 6 | samba-0:4.6.3-6.el6rhs | Fixed | RHSA-2017:2858 |
| Red Hat Gluster Storage 3.3 for RHEL 7 | samba-0:4.6.3-6.el7rhgs | Fixed | RHSA-2017:2858 |
| Red Hat Enterprise Linux 5 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 5 | samba3x | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The samba4 package in Red Hat Enterprise Linux 6, is a tech preview and by default uses the SMB1 protocol, therefore though affected by this flaw, will not be addressed in a security update.
Red Hat mitigation
Keep the default of "client max protocol = NT1".
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
AV:N/AC:M/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (30 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.59% (0.04595) | 91.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.59% (0.04595) | 90.41th | v5 (v2026.06.15) |
| Jun 8, 2026 | 5.27% (0.05265) | 90.17th | v4 (v2025.03.14) |
| Mar 13, 2026 | 4.15% (0.04146) | 88.49th | v4 (v2025.03.14) |
| Mar 10, 2026 | 2.97% (0.02966) | 86.29th | v4 (v2025.03.14) |
| Jan 25, 2026 | 8.03% (0.08030) | 91.88th | v4 (v2025.03.14) |
| Jan 20, 2026 | 9.12% (0.09120) | 92.42th | v4 (v2025.03.14) |
| Nov 30, 2025 | 8.03% (0.08030) | 91.77th | v4 (v2025.03.14) |
| Oct 19, 2025 | 4.03% (0.04028) | 87.94th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.14% (0.02141) | 82.67th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.16% (0.03157) | 78.07th | v4 (v2025.03.14) |
| Mar 20, 2025 | 2.14% (0.02141) | 82.75th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.63% (0.05630) | 89.66th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.22% (0.00222) | 61.41th | v3 (v2023.03.01) |
| Feb 20, 2024 | 0.22% (0.00222) | 59.64th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.28% (0.00283) | 67.75th | v3 (v2023.03.01) |
| Jan 27, 2024 | 0.28% (0.00283) | 65.40th | v3 (v2023.03.01) |
| Dec 18, 2023 | 0.34% (0.00336) | 68.17th | v3 (v2023.03.01) |
| Nov 26, 2023 | 0.36% (0.00362) | 69.24th | v3 (v2023.03.01) |
| Jul 21, 2023 | 0.51% (0.00513) | 73.54th | v3 (v2023.03.01) |
| May 8, 2023 | 0.53% (0.00529) | 73.59th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.34% (0.00345) | 67.09th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.54% (0.01537) | 74.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.54% (0.01537) | 51.33th | v2 (v2022.01.01) |
| Feb 3, 2022 | 9.63% (0.09628) | 87.22th | v1 |
| Jan 6, 2022 | 9.63% (0.09628) | 87.07th | v1 |
| Sep 1, 2021 | 9.63% (0.09628) | 94.88th | v1 |
| Apr 14, 2021 | 9.63% (0.09628) | 0.00th | v1 |
References (13)
- http://www.securityfocus.com/bid/100917 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039401 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2790 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2858 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-12151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1488197 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-12151
- https://security.netapp.com/advisory/ntap-20170921-0001/ x_refsource_CONFIRMThird Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-12151
- https://www.debian.org/security/2017/dsa-3983 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.samba.org/samba/security/CVE-2017-12151.html x_refsource_CONFIRMMitigationVendor Advisory
Change history (0)
No recorded changes yet.