Unrated severityNVD Advisory· Published Jul 20, 2023· Updated Nov 20, 2025
Samba: smb2 packet signing is not enforced when "server signing = required" is set
CVE-2023-3347
Description
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the network traffic and modifying the SMB2 messages between client and server, affecting the integrity of the data.
Affected products
43cpe:/a:redhat:enterprise_linux:9::appstream+ 3 more
- cpe:/a:redhat:enterprise_linux:9::appstreamrange: 0:4.17.5-103.el9_2
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- cpe:/o:redhat:enterprise_linux:8::baseosrange: 0:4.17.5-3.el8_8
- Red Hat/Red Hat Storage 3v5cpe:/a:redhat:storage:3
- osv-coords38 versionspkg:rpm/almalinux/ctdbpkg:rpm/almalinux/libnetapipkg:rpm/almalinux/libnetapi-develpkg:rpm/almalinux/libsmbclientpkg:rpm/almalinux/libsmbclient-develpkg:rpm/almalinux/libwbclientpkg:rpm/almalinux/libwbclient-develpkg:rpm/almalinux/python3-sambapkg:rpm/almalinux/python3-samba-dcpkg:rpm/almalinux/python3-samba-develpkg:rpm/almalinux/python3-samba-testpkg:rpm/almalinux/sambapkg:rpm/almalinux/samba-clientpkg:rpm/almalinux/samba-client-libspkg:rpm/almalinux/samba-commonpkg:rpm/almalinux/samba-common-libspkg:rpm/almalinux/samba-common-toolspkg:rpm/almalinux/samba-dcerpcpkg:rpm/almalinux/samba-dc-libspkg:rpm/almalinux/samba-develpkg:rpm/almalinux/samba-krb5-printingpkg:rpm/almalinux/samba-ldb-ldap-modulespkg:rpm/almalinux/samba-libspkg:rpm/almalinux/samba-pidlpkg:rpm/almalinux/samba-testpkg:rpm/almalinux/samba-test-libspkg:rpm/almalinux/samba-toolspkg:rpm/almalinux/samba-usersharespkg:rpm/almalinux/samba-vfs-iouringpkg:rpm/almalinux/samba-winbindpkg:rpm/almalinux/samba-winbind-clientspkg:rpm/almalinux/samba-winbind-krb5-locatorpkg:rpm/almalinux/samba-winbind-modulespkg:rpm/almalinux/samba-winexepkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5
< 4.17.5-103.el9_2.alma+ 37 more
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.5-103.el9_2.alma
- (no CPE)range: < 4.17.9+git.367.dae41ffdd1f-150500.3.5.1
- (no CPE)range: < 4.18.5+git.313.c8e274c7852-1.1
- (no CPE)range: < 4.17.9+git.367.dae41ffdd1f-150500.3.5.1
- (no CPE)range: < 4.17.9+git.367.dae41ffdd1f-150500.3.5.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- access.redhat.com/errata/RHSA-2023:4325mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2023:4328mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2023-3347mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
- www.samba.org/samba/security/CVE-2023-3347.htmlmitre
News mentions
0No linked articles in our index yet.