libcli/smb/smbXcli_base.c in Samba 4.x prior to 4.2.14, 4.3.x prior to 4.3.11, and 4.4.x prior to 4.4.5 allows man-in-the-middle malicious users to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
samba samba |