Dell KACE K2000 Appliance Hidden CIFS Fileshare Information Disclosure

medium Nessus Plugin ID 53493

Synopsis

The remote deployment appliance has an information disclosure vulnerability.

Description

The remote Dell KACE K2000 appliance has an information disclosure vulnerability. A hidden, read-only share named 'peinst' is used to facilitate Windows deployments. This share is populated with pre- and post-installation tasks, as well as deployment bootfiles and media used for Windows network installs. This share allows anonymous access.

A remote, unauthenticated attacker could connect to this share, allowing them to access sensitive data used during deployments (e.g.
local and/or domain administrator credentials).

Solution

Upgrade to K2000 3.4 or later.

See Also

http://www.kace.com/support/kb/index.php?action=artikel&cat=1&id=1104

http://www.nessus.org/u?7a694232

Plugin Details

Severity: Medium

ID: 53493

File Name: dell_kace_hidden_share.nasl

Version: 1.12

Type: remote

Family: Misc.

Published: 4/19/2011

Updated: 3/9/2020

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2011-1672

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:dell:kace_k2000_systems_deployment_appliance

Required KB Items: SMB/samba, SMB/guest_enabled

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/5/2011

Reference Information

CVE: CVE-2011-1672

BID: 47172

CERT: 598700