Back

MEDIUM

Samba: smb2 packet signing is not enforced when "server signing = required" is set

Published Jul 20, 2023

Description

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.

Affected products

Remediation

Red Hat statement

This CVE only affects Samba starting with 4.17.0 and higher versions.

Weaknesses (2)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 20, 2023
Updated Nov 20, 2025
Reserved Jun 21, 2023
CISA Vulnrichment
Updated Apr 25, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 19, 2023
ENISA EUVD
Assigner redhat
Published Jul 20, 2023
Updated Nov 20, 2025
Exploited since n/a
EUVD-2023-44015