H3-2021-0030
SMB Signing Not Required
Category | SECURITY_MISCONFIGURATION |
Base Score | 1.0 |
Description
The SMB server does not require signing
Impact
SMB signing is a security feature in the SMB protocol that enables SMB clients and servers to validate the authenticity and integrity of communication. When SMB signing is not required, it is possible for attackers to conduct man-in-the-middle attacks that intercept, modify, and relay communication. This can lead to attackers gaining domain account privileges and host access.