Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Cody Green

#49706de 53,638
5CVSS total
Vulnerabilidades · 1
PT-2011-3283
5.0
2011-04-10
Dell · Dell Kace K2000 System Deployment Appliance · CVE-2011-1672
**Name of the Vulnerable Software and Affected Versions** Dell KACE K2000 Systems Deployment Appliance versions 3.3.36822 and earlier **Description** The issue allows remote attackers to obtain sensitive information by reading certain files. Specifically, attackers can read the `unattend.xml` or `sysprep.inf` file, which may contain sensitive data such as passwords. **Recommendations** For Dell KACE K2000 Systems Deployment Appliance versions 3.3.36822 and earlier, consider restricting access to the peinst CIFS share as a temporary workaround until a patch is available. Additionally, limit access to sensitive files such as `unattend.xml` and `sysprep.inf` to minimize the risk of exploitation.