NetInfo Arbitrary Remote File Access

medium Nessus Plugin ID 11898

Language:

Synopsis

The remote service is prone to an information disclosure flaw.

Description

Using NetInfo, it is possible to obtain the password file of the remote host by querying it directly.

An attacker may use it to set up a brute-force attack to crack the passwords contained in the file, and then use the gained passwords to login into the remote host, either remotely or locally.

Solution

Restrict access to NetInfo.

See Also

https://marc.info/?l=bugtraq&m=99953038722104&w=2

Plugin Details

Severity: Medium

ID: 11898

File Name: netinfo_passwd.nasl

Version: 1.24

Type: remote

Family: Misc.

Published: 10/19/2003

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Required KB Items: Services/netinfo

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 6/26/2001

Reference Information

CVE: CVE-2001-1412

BID: 2953