Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxm3-fp55-pm48

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

EPSS

Процентиль: 83%
0.01965
Низкий

8.1 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 7 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 5.4
redhat
почти 7 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
nvd
почти 7 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
debian
почти 7 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the u ...

CVSS3: 8.1
fstec
почти 7 лет назад

Уязвимость компонента аутентификации NTLMv1 программ сетевого взаимодействия Samba, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным

EPSS

Процентиль: 83%
0.01965
Низкий

8.1 High

CVSS3

Дефекты

CWE-522