Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)

info Nessus Plugin ID 96982

Synopsis

The remote host supports the SMBv1 protocol.

Description

The remote host (Windows and/or Samba server) supports Server Message Block Protocol version 1 (SMBv1). Microsoft recommends that users discontinue the use of SMBv1 due to the lack of security features that were included in later SMB versions. Additionally, most security and compliance agencies recommend that users disable SMBv1 per SMB best practices.

Solution

Disable SMBv1 according to the vendor instructions in Microsoft KB2696547. Additionally, block SMB directly by blocking TCP port 445 on all network boundary devices. For SMB over the NetBIOS API, block TCP ports 137 / 139 and UDP ports 137 / 138 on all network boundary devices.

See Also

http://www.nessus.org/u?59bfc3ef

http://www.nessus.org/u?b9d9ebf9

http://www.nessus.org/u?8dcab5e4

http://www.nessus.org/u?234f8ef8

http://www.nessus.org/u?4c7e0cf3

Plugin Details

Severity: Info

ID: 96982

File Name: smb_v1_enabled_remote.nasl

Version: 1.8

Type: remote

Family: Misc.

Published: 2/3/2017

Updated: 8/13/2025

Supported Sensors: Nessus

Vulnerability Information

Required KB Items: SMB/SMBv1_is_supported

Reference Information

IAVT: 0001-T-0710