CyberRota Analysis
AI-GeneratedThe jCIFS client in affected versions of Spring Integration defaults to negotiating SMB1/CIFS unless explicitly configured to use a higher minimum SMB version, exposing the application to risks such as NTLM relay attacks and content tampering through man-in-the-middle (MITM) vulnerabilities. Organizations using these versions should prioritize updating their configurations to enforce a minimum SMB version to mitigate these security risks. This vulnerability is particularly relevant for those managing file sharing and network communication within their Spring Integration environments.
Original NVD Description
Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Related CVEs
Other vulnerabilities affecting the same vendor(s)