Got it

Vulnerability Scan Software Prompts that CIFS Ports Have Signature Vulnerabilities

95 0 0 0 0

[Symptom Description]

During vulnerability scanning, if the CIFS service IP address of the V3 storage is added, an alarm is generated, indicating that SMB Signing Disabled.


[Alarm Information]

No alarm is generated on the storage device.


[Cause Description]

This alarm is generated because the storage CIFS service signature function is disabled. You can enable the signature function on DeviceManager and perform the test again.

SMB1.0 is rarely used (WinXP has stopped supporting services). Therefore, SMB1.0 is disabled by default. After this function is enabled, the SMB1.0 performance is affected because the interaction process increases.

After this function is enabled, if the signature takes effect, you need to remount the CIFS share. If the CIFS share is not mounted, existing services are not affected. However, the vulnerability is not displayed during rescan.


[Troubleshooting Roadmap]

When a customer uses vulnerability scanning software to scan the storage CIFS share service, a message is displayed indicating that the SMB Signing Disabled vulnerability exists.


[Solution]

Enable the SMB1.0 signature function. Choose Settings > Storage Settings > CIFS Service > Signature Settings > Signature. Select the option and scan again. The vulnerability alarm is cleared.


[Post-Recovery Check]

Use the vulnerability scanning tool to scan again. The alarm is cleared.

Comment

You need to log in to comment to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.