CVE Vulnerabilities

CVE-2016-2114

Published: Apr 25, 2016 | Modified: Dec 31, 2016
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the server signing = mandatory setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client-server data stream.

Affected Software

Name Vendor Start Version End Version
Samba Samba 4.0.0 (including) 4.0.0 (including)
Samba Samba 4.0.1 (including) 4.0.1 (including)
Samba Samba 4.0.2 (including) 4.0.2 (including)
Samba Samba 4.0.3 (including) 4.0.3 (including)
Samba Samba 4.0.4 (including) 4.0.4 (including)
Samba Samba 4.0.5 (including) 4.0.5 (including)
Samba Samba 4.0.6 (including) 4.0.6 (including)
Samba Samba 4.0.7 (including) 4.0.7 (including)
Samba Samba 4.0.8 (including) 4.0.8 (including)
Samba Samba 4.0.9 (including) 4.0.9 (including)
Samba Samba 4.0.10 (including) 4.0.10 (including)
Samba Samba 4.0.11 (including) 4.0.11 (including)
Samba Samba 4.0.12 (including) 4.0.12 (including)
Samba Samba 4.0.13 (including) 4.0.13 (including)
Samba Samba 4.0.14 (including) 4.0.14 (including)
Samba Samba 4.0.15 (including) 4.0.15 (including)
Samba Samba 4.0.16 (including) 4.0.16 (including)
Samba Samba 4.0.17 (including) 4.0.17 (including)
Samba Samba 4.0.18 (including) 4.0.18 (including)
Samba Samba 4.0.19 (including) 4.0.19 (including)
Samba Samba 4.0.20 (including) 4.0.20 (including)
Samba Samba 4.0.21 (including) 4.0.21 (including)
Samba Samba 4.0.22 (including) 4.0.22 (including)
Samba Samba 4.0.23 (including) 4.0.23 (including)
Samba Samba 4.0.24 (including) 4.0.24 (including)
Samba Samba 4.0.25 (including) 4.0.25 (including)
Samba Samba 4.0.26 (including) 4.0.26 (including)
Samba Samba 4.1.0 (including) 4.1.0 (including)
Samba Samba 4.1.1 (including) 4.1.1 (including)
Samba Samba 4.1.2 (including) 4.1.2 (including)
Samba Samba 4.1.3 (including) 4.1.3 (including)
Samba Samba 4.1.4 (including) 4.1.4 (including)
Samba Samba 4.1.5 (including) 4.1.5 (including)
Samba Samba 4.1.6 (including) 4.1.6 (including)
Samba Samba 4.1.7 (including) 4.1.7 (including)
Samba Samba 4.1.8 (including) 4.1.8 (including)
Samba Samba 4.1.9 (including) 4.1.9 (including)
Samba Samba 4.1.10 (including) 4.1.10 (including)
Samba Samba 4.1.11 (including) 4.1.11 (including)
Samba Samba 4.1.12 (including) 4.1.12 (including)
Samba Samba 4.1.13 (including) 4.1.13 (including)
Samba Samba 4.1.14 (including) 4.1.14 (including)
Samba Samba 4.1.15 (including) 4.1.15 (including)
Samba Samba 4.1.16 (including) 4.1.16 (including)
Samba Samba 4.1.17 (including) 4.1.17 (including)
Samba Samba 4.1.18 (including) 4.1.18 (including)
Samba Samba 4.1.19 (including) 4.1.19 (including)
Samba Samba 4.1.20 (including) 4.1.20 (including)
Samba Samba 4.1.21 (including) 4.1.21 (including)
Samba Samba 4.1.22 (including) 4.1.22 (including)
Samba Samba 4.1.23 (including) 4.1.23 (including)
Samba Samba 4.2.0-rc1 (including) 4.2.0-rc1 (including)
Samba Samba 4.2.0-rc2 (including) 4.2.0-rc2 (including)
Samba Samba 4.2.0-rc3 (including) 4.2.0-rc3 (including)
Samba Samba 4.2.0-rc4 (including) 4.2.0-rc4 (including)
Samba Samba 4.2.1 (including) 4.2.1 (including)
Samba Samba 4.2.2 (including) 4.2.2 (including)
Samba Samba 4.2.3 (including) 4.2.3 (including)
Samba Samba 4.2.4 (including) 4.2.4 (including)
Samba Samba 4.2.5 (including) 4.2.5 (including)
Samba Samba 4.2.6 (including) 4.2.6 (including)
Samba Samba 4.2.7 (including) 4.2.7 (including)
Samba Samba 4.2.8 (including) 4.2.8 (including)
Samba Samba 4.2.9 (including) 4.2.9 (including)
Samba Samba 4.3.0 (including) 4.3.0 (including)
Samba Samba 4.3.1 (including) 4.3.1 (including)
Samba Samba 4.3.2 (including) 4.3.2 (including)
Samba Samba 4.3.3 (including) 4.3.3 (including)
Samba Samba 4.3.4 (including) 4.3.4 (including)
Samba Samba 4.3.5 (including) 4.3.5 (including)
Samba Samba 4.3.6 (including) 4.3.6 (including)
Samba Samba 4.4.0 (including) 4.4.0 (including)

References