Impact
The jCIFS client used by Spring Integration negotiates the SMB1 protocol dialect unless the application explicitly raises the minimum SMB version. SMB1 lacks mandatory signing and encryption, making the connection vulnerable to NTLM relay attacks and content‑tampering by a man‑in‑the‑middle. This weakness can be exploited to intercept or modify data sent over the SMB session, potentially compromising confidentiality and integrity of file transfers or other SMB operations.
Affected Systems
Spring Integration versions 7.1.0, 7.0.0 through 7.0.5, 6.5.0 through 6.5.10, and 6.4.0 through 6.4.12 are affected by this protocol‑downgrade issue.
Risk and Exploitability
The CVSS score is 6.6, indicating a moderate risk. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need network access to an SMB endpoint and the ability to negotiate protocol versions; by default the client off‑loads to SMB1, enabling MITM and NTLM relay attacks without requiring special privileges.
OpenCVE Enrichment