ID

VAR-200511-0342


CVE

CVE-2005-3786


TITLE

Novell ZENworks remote diagnosis Console One Unauthorized access vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200511-359

DESCRIPTION

Novell ZENworks for Desktops 4.0.1, ZENworks for Servers 3.0.2, and ZENworks 6.5 Desktop Management does not restrict access to Remote Diagnostics, which allows local users to bypass security policies by using Console One. Novell ZENworks Remote Diagnostics is prone to an unauthorized access vulnerability. This vulnerability may facilitate disclosure of sensitive data and may aid in other attacks against a vulnerable computer. http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972567.htm PROVIDED AND/OR DISCOVERED BY: Reported by vendor. ORIGINAL ADVISORY: http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098818.htm ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 1.26

sources: NVD: CVE-2005-3786 // BID: 15540 // PACKETSTORM: 41767

AFFECTED PRODUCTS

vendor:novellmodel:zenworks serversscope:eqversion:3.0.2

Trust: 1.6

vendor:novellmodel:zenworks desktopsscope:eqversion:4.0.1

Trust: 1.6

vendor:novellmodel:zenworksscope:eqversion:6.5

Trust: 1.6

vendor:novellmodel:zenworks remote managementscope: - version: -

Trust: 0.3

vendor:novellmodel:zenworks for serversscope:eqversion:3.0.2

Trust: 0.3

vendor:novellmodel:zenworks for desktopsscope:eqversion:4.0.1

Trust: 0.3

vendor:novellmodel:zenworks desktop managementscope:eqversion:6.5

Trust: 0.3

vendor:novellmodel:zenworks for servers ir4scope:neversion:3.0.2

Trust: 0.3

sources: BID: 15540 // CNNVD: CNNVD-200511-359 // NVD: CVE-2005-3786

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2005-3786
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200511-359
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2005-3786
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-200511-359 // NVD: CVE-2005-3786

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2005-3786

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-200511-359

TYPE

access verification error

Trust: 0.6

sources: CNNVD: CNNVD-200511-359

EXTERNAL IDS

db:BIDid:15540

Trust: 1.9

db:SECUNIAid:17700

Trust: 1.7

db:VUPENid:ADV-2005-2544

Trust: 1.6

db:SECTRACKid:1015260

Trust: 1.6

db:NVDid:CVE-2005-3786

Trust: 1.6

db:CNNVDid:CNNVD-200511-359

Trust: 0.6

db:PACKETSTORMid:41767

Trust: 0.1

sources: BID: 15540 // PACKETSTORM: 41767 // CNNVD: CNNVD-200511-359 // NVD: CVE-2005-3786

REFERENCES

url:http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098818.htm

Trust: 2.0

url:http://secunia.com/advisories/17700

Trust: 1.6

url:http://www.securityfocus.com/bid/15540

Trust: 1.6

url:http://securitytracker.com/id?1015260

Trust: 1.6

url:http://www.vupen.com/english/advisories/2005/2544

Trust: 1.0

url:http://www.frsirt.com/english/advisories/2005/2544

Trust: 0.6

url:http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972567.htm

Trust: 0.4

url:http://www.novell.com/products/zenworks/

Trust: 0.3

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/product/1246/

Trust: 0.1

url:http://secunia.com/product/1247/

Trust: 0.1

url:http://secunia.com/product/4134/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/17700/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

sources: BID: 15540 // PACKETSTORM: 41767 // CNNVD: CNNVD-200511-359 // NVD: CVE-2005-3786

CREDITS

Novell

Trust: 0.6

sources: CNNVD: CNNVD-200511-359

SOURCES

db:BIDid:15540
db:PACKETSTORMid:41767
db:CNNVDid:CNNVD-200511-359
db:NVDid:CVE-2005-3786

LAST UPDATE DATE

2024-08-14T15:20:08.990000+00:00


SOURCES UPDATE DATE

db:BIDid:15540date:2005-11-23T00:00:00
db:CNNVDid:CNNVD-200511-359date:2005-11-29T00:00:00
db:NVDid:CVE-2005-3786date:2011-03-08T02:27:10.377

SOURCES RELEASE DATE

db:BIDid:15540date:2005-11-23T00:00:00
db:PACKETSTORMid:41767date:2005-11-30T04:03:08
db:CNNVDid:CNNVD-200511-359date:2005-11-23T00:00:00
db:NVDid:CVE-2005-3786date:2005-11-23T23:03:00