CVE-2011-1672: Infoleak
The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1672?
CVE-2011-1672 is considered a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2011-1672?
To fix CVE-2011-1672, upgrade the Dell KACE K2000 Systems Deployment Appliance to a version later than 3.3.36822.
What files can be accessed due to CVE-2011-1672?
CVE-2011-1672 allows remote attackers to access sensitive files such as unattend.xml and sysprep.inf.
Who is affected by CVE-2011-1672?
Organizations using Dell KACE K2000 Systems Deployment Appliance versions 3.3.36822 and earlier are affected by CVE-2011-1672.
What is the impact of CVE-2011-1672?
The impact of CVE-2011-1672 is the unauthorized disclosure of sensitive configuration files, potentially leading to credential exposure.