Document Title: =============== DELL KBOX SM Appliance v5.1.x - Multiple Vulnerabilities References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id= Release Date: ============= 2011-07-28 Vulnerability Laboratory ID (VL-ID): ==================================== 70 Common Vulnerability Scoring System: ==================================== 3.8 Product & Service Introduction: =============================== The KACE Management Appliance delivers a fully integrated systems management solution, unlike traditional software approaches that can require complex and time-consuming deployment and maintenance. KACE accomplishes this via an extremely flexible, intelligent appliance-based architecture that typically deploys in days and is self maintaining. The KACE Management Appliance also provides direct access to time-saving AppDeploySM systems management community information using AppDeploy Live, the leading destination for end point administrators. The result: Comprehensive systems management that is easy-to-use and that can be more economical than software only alternatives. Read more in the white paper KACE K1000 Management Appliance Architecture: Harnessing the Power of an Appliance-based Architecture. Screenshots: http://www.kace.com/products/systems-management-appliance/screenshots/ (Copy of the Vendor Homepage: http://www.kace.com/products/systems-management-appliance/) Abstract Advisory Information: ============================== Vulnerability-Lab Research Team discovered multiple persistent Web Vulnerabilities on the Dell KACE Management Appliance. Vulnerability Disclosure Timeline: ================================== 2011-07-29: Public or Non-Public Disclosure Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== Low Technical Details & Description: ================================ Multiple input validation vulnerabilities(persistent) are detected on Dell Kace Systems - Management Appliance. Attackers can include (persistent) malicious script codes to manipulate specific customer requests & sections. It is also possible to hijack customer sessions with persistent script code attacks. Vulnerable Modules: (Persistent) [+] MSP Inventory [+] Patch2 [+] Queue [+] Report List [+] Report Schedule [+] settings linking Pictures/Screens: ../Pictures/1.png ../Pictures/2.png ../Pictures/3.png Proof of Concept (PoC): ======================= he vulnerabilities can be exploited by remote attackers with or without user inter-action. For demonstration or reproduce ... Code Review: MSP Inventory (Persistent) ID [labels hidden] Title (short) Release Date Impact Reboot · · Unpatched  
Info...

No patches currently available.

About KBOX  |  © 2010 Dell Inc.Thu, 22 Jul 2010 12:54:45 CDT   Report Bug