First published: Sun Apr 10 2011(Updated: )
The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE Systems Deployment Appliance | <=3.3.36822 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1672 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2011-1672, upgrade the Dell KACE K2000 Systems Deployment Appliance to a version later than 3.3.36822.
CVE-2011-1672 allows remote attackers to access sensitive files such as unattend.xml and sysprep.inf.
Organizations using Dell KACE K2000 Systems Deployment Appliance versions 3.3.36822 and earlier are affected by CVE-2011-1672.
The impact of CVE-2011-1672 is the unauthorized disclosure of sensitive configuration files, potentially leading to credential exposure.