cancel
Showing results for 
Search instead for 
Did you mean: 

The SMBv1 vulnerability has been detected on the Prognosis servers

The SMBv1 vulnerability has been detected on the Prognosis servers

Description:  

 

  • Customer stated they've recently received an email notification from their Cyber Security indicating that SMBv1 does not support encryption.  That means that any attacker who steals a password and logs into an endpoint can capture SMB 1 traffic, view it in plaintext, and even modify the stream to send false commands.

Analysis:

 

  • Cyber security team warned the customer if Prognosis is still using SMBv1, they will shut down the SMBv1 before this exploit and it requires server reboot to take effect.
  • Customer just wanted to check with IR to ensure Prognosis will not be affected by shutting down SMBv1.

Resolution:

​​​​​​​

  • SMB is how windows servers share and connect to file shares and printers. SMB v1 is the first version of WMB. It is almost 30 years old and is not used in current supported versions of MS Windows.
  • If this comes up in your scan, you can disable SMBv1 as Prognosis does not use SMB

screenshot.png

If my answer helped you today, please give my post a like and be sure to mark the 'Accept Solution' button to help others find the answer!
Cheers
Andy Gjertsen
Tags (2)
1 ACCEPTED SOLUTION

Accepted Solutions

Re: The SMBv1 vulnerability has been detected on the Prognosis servers

**Resolution from previous post**

 

  • SMB is how windows servers share and connect to file shares and printers. SMB v1 is the first version of WMB. It is almost 30 years old and is not used in current supported versions of MS Windows.
  • If this comes up in your scan, you can disable SMBv1 as Prognosis does not use SMB

 

If my answer helped you today, please give my post a like and be sure to mark the 'Accept Solution' button to help others find the answer!
Cheers
Andy Gjertsen

View solution in original post

1 REPLY 1

Re: The SMBv1 vulnerability has been detected on the Prognosis servers

**Resolution from previous post**

 

  • SMB is how windows servers share and connect to file shares and printers. SMB v1 is the first version of WMB. It is almost 30 years old and is not used in current supported versions of MS Windows.
  • If this comes up in your scan, you can disable SMBv1 as Prognosis does not use SMB

 

If my answer helped you today, please give my post a like and be sure to mark the 'Accept Solution' button to help others find the answer!
Cheers
Andy Gjertsen
Webinar: Keep the modern workforce connected

Unified Communications has always been an important part of companies' digital transformation efforts due to its ability to enable rich virtual collaboration and communication. But with COVID-19, we've reached a break-through point.

Join Bill Haskins, Sr. Analyst & Partner, Unified Communications at Wainhouse Research, and John Ruthven, CEO at IR discuss UC challenges companies are experiencing due to the COVOID-19 crisis.

Join webinar
Top Liked Members