Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
  • 1.  FIX for "SMB signing is not required" vulnerability

    Posted 3 days ago

    Hello All

    I need vulnerable fix for the "SMB signing is not required" on AIX. Please help



    ------------------------------
    goverdhana musunuri
    ------------------------------


  • 2.  RE: FIX for "SMB signing is not required" vulnerability

    Posted 3 days ago

    Please be more clear here. What is the CVE and which product is affected by it ? 



    ------------------------------
    Ayappan P
    ------------------------------



  • 3.  RE: FIX for "SMB signing is not required" vulnerability

    Posted 2 days ago

    Hi Ayappan

    Samba configured on the AIX 7.2 servers for CIFS mounts. Our scanner not provided any CVE. But, I checked with IBM for remediation for this vulnerability. They mentioned that there is no direct support other than forums.

    Regards

    Goverdhana



    ------------------------------
    goverdhana musunuri
    ------------------------------



  • 4.  RE: FIX for "SMB signing is not required" vulnerability

    Posted yesterday

    Are you using AIX Toolbox Samba ? It doesn't have CIFS mount capabilities. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 5.  RE: FIX for "SMB signing is not required" vulnerability

    Posted yesterday

    Talk to your scanner provider.  It's 2025, generic failures aren't acceptable, they must provide something that identifies the actual problem, ideally a CVE or a vendor information page regarding the identified problem.

    In this case, check smb.conf, the global stanza should have:

    client signing = required
    server signing = mandatory



    ------------------------------
    José Pina Coelho
    IT Specialist at Kyndryl
    ------------------------------