The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/47172 | vdb entry |
http://www.kb.cert.org/vuls/id/598700 | third party advisory us government resource |
http://www.vupen.com/english/advisories/2011/0883 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/66630 | vdb entry |
http://www.kace.com/support/kb/index.php?action=artikel&cat=1&id=1104 | vendor advisory |