VendorsDellkace_k2000_systems_deployment_applianceany version
Vulnerabilities

Dell Kace k2000 Systems Deployment Appliance any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2011-4047
The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.
Published 2011-11-12 · Modified
9.3EPSS 0.033
CVE-2011-1672
The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password.
Published 2011-04-10 · Modified
5.0EPSS 0.025
CVE-2011-4046
The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by examining script source code.
Published 2011-11-12 · Modified
5.0EPSS 0.013
CVE-2011-4048
The Dell KACE K2000 System Deployment Appliance has a default username and password for the read-only reporting account, which makes it easier for remote attackers to obtain sensitive information from the database by leveraging the default credentials.
Published 2011-11-12 · Modified
4.3EPSS 0.011
CVE-2011-4436
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2011-11-12 · Modified
3.5EPSS 0.007