<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Disable SMB1 support in Samba</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-17-103</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2019-06-04T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2019-06-04T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2019-06-04T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            Server Message Block (SMB) 1.0 - a legacy file and print sharing protocol - has been deprecated by Microsoft due to multiple weaknesses (remote code execution, downgrade, man-in-the-middle, collision and pre-image attack).While it is only used as a client in FortiOS, as a measure of precaution SMBv1 support in FortiOS SSL-VPN and DLP is now disabled by default starting from 6.0.1 [1][2] and 5.6.6 [3] for High-End models (FortiGate 1000 series and higher models) and Virtual Machine models and can be re-enabled by applying the following CLI commands (not recommended):[1] FortiOS 6.2 branch (6.2.0 and above):&#39;&#39;&#39;conf vpn ssl web portaledit {portal-name} set smb-min-version smbv1 # (note: default value is &amp;quot;smbv2&amp;quot;) set smb-max-version smbv1 # (note: default value is &amp;quot;smbv3&amp;quot;) nextend &#39;&#39;&#39;[2] FortiOS 6.0 branch (6.0.1 and above):&#39;&#39;&#39;conf vpn ssl web portaledit {portal-name} set smbv1 enable # (note: default value is &amp;ldquo;disable&amp;rdquo;)nextend &#39;&#39;&#39;[3] FortiOS 5.6 branch (5.6.6 and above):&#39;&#39;&#39;config vpn ssl web portaledit {portal-name} set smb-ntlmv1-auth enable # (note: default value is &amp;ldquo;disable&amp;rdquo;)nextend &#39;&#39;&#39;(For FortiOS 5.6.5 and below versions, the smb-ntlmv1-auth CLI command can not disable SMBv1 protocol support).SMBv1 support is also disabled by default in the FortiOS FSSO fsso-polling feature starting from 6.2.0 [4] for High-End models and Virtual Machine models and can be enabled by applying the following CLI commands:[4] FortiOS 6.2.0 branch:&#39;&#39;&#39;config user fsso-pollingset smbv1 {enable|*disable} # (default value is &amp;quot;disable&amp;quot;)end &#39;&#39;&#39;For Entry-Levels and Mid-Range models, SMBv1 remains the only supported SMB protocol.
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="2">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="3">
            FortiOS High-End models and Virtual Machine models: FortiOS 6.0.0, 5.6.5 and below.FortiOS Entry-Levels and Mid-Range models: FortiOS all versions.At leastFortiMail version 5.3.13At leastFortiAuthenticator 5.0 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            FortiOS:For High-End models and Virtual Machine models, upgrade to FortiOS 6.0.1, 5.6.6 or newer versions.For Entry-Levels and Mid-Range models, starting from FortiOS 5.6.11, 6.0.7 and 6.2.1, when SMBv1 is used under the SSL VPN web portal, a warning bar will be shown to the user under login page and later pages, alerting about using a deprecated and unsafe SMBv1 protocol.Details of FortiOS model specifications: https://www.fortinet.com/products/next-generation-firewall/models-specs.htmlFortiMail:Upgrade to FortiMal 5.4.0 or newer versionsFortiAuthenticator:Upgrade to FortiAuthenticator 5.1.0 or newer versionsRevision History:08-08-2017 Initial version06-04-2019 New CLI commands and security warning bar introduced08-22-2019 Update warning bar introduced branch versions.04-20-2023 Reformatted, added missing platforms in SA body to match info table
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-17-103</cvrf:URL>
            <cvrf:Description>Disable SMB1 support in Samba</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>https://blogs.technet.microsoft.com/josebda/2015/04/21/the-deprecation-of-smb1-you-should-be-planning-to-get-rid-of-this-old-smb-dialect/</cvrf:URL>
            <cvrf:Description>https://blogs.technet.microsoft.com/josebda/2015/04/21/the-deprecation-of-smb1-you-should-be-planning-to-get-rid-of-this-old-smb-dialect/</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>https://docs.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010</cvrf:URL>
            <cvrf:Description>https://docs.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <Vulnerability Ordinal="1">
        <Title>Disable SMB1 support in Samba</Title>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>7.3</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-17-103</URL>
                <Description>Disable SMB1 support in Samba</Description>
            </Reference>Reference>
            <Reference>
                <URL>https://blogs.technet.microsoft.com/josebda/2015/04/21/the-deprecation-of-smb1-you-should-be-planning-to-get-rid-of-this-old-smb-dialect/</URL>
                <Description>https://blogs.technet.microsoft.com/josebda/2015/04/21/the-deprecation-of-smb1-you-should-be-planning-to-get-rid-of-this-old-smb-dialect/</Description>
            </Reference>
            <Reference>
                <URL>https://docs.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010</URL>
                <Description>https://docs.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>