6.6
CVE-2026-59293
- EPSS 0.22%
- Veröffentlicht 27.08.2026 17:57:51
- Zuletzt bearbeitet 31.08.2026 23:14:00
- Erkennungen
SMB minimum protocol dialect defaults to SMB1
Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Integration Version >= 6.4.0 < 6.4.13
VMware ≫ Spring Integration Version >= 6.5.0 < 6.5.11
VMware ≫ Spring Integration Version >= 7.0.0 < 7.0.5.1
VMware ≫ Spring Integration Version >= 7.1.0 < 7.1.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.125 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
https://spring.io/security/cve-2026-59293