ZeroHour

CVE-2018-1139

CVSS 3.1
8.1 high
EPSS
3%p87
Published
()
Modified
Description

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

Vendors
sambacanonicalredhat
Products
samba, ubuntu linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-20, CWE-522
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.