First published: Sat Nov 12 2011(Updated: )
The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by examining script source code.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE Systems Deployment Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4046 is classified as a medium severity vulnerability due to the risk of password exposure.
To fix CVE-2011-4046, ensure that sensitive information is not stored in cleartext and implement secure coding practices.
The vulnerability affects users of the Dell KACE K2000 System Deployment Appliance that have not mitigated the cleartext password storage issue.
CVE-2011-4046 can be exploited by attackers with access to the source code of the PHP script containing sensitive information.
CVE-2011-4046 was disclosed in 2011, highlighting a security flaw associated with the Dell KACE K2000 Systems Deployment Appliance.