What the vulnerability does

01Description

A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.

Key dates

02Disclosure timeline

February 18, 2022 CVE published
August 5, 2024 Record updated