CVE-2018-1139
HIGHSamba <4.7.9, 4.8.4 - Info Disclosure
Title source: llmDescription
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
References (9)
Scores
CVSS v3
8.1
EPSS
0.0162
EPSS Percentile
81.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
CWE-20
Status
published
Affected Products (7)
samba/samba
< 4.7.9
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation
Timeline
Published
Aug 22, 2018
Tracked Since
Feb 18, 2026