27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Skype Temporary File Arbitrary File Overwrite<br />

<strong>PVS</strong> ID: 3070 FAMILY: Internet Messengers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a local flaw in the way that it protects data<br />

files.\n\nThe remote host is using Skype, a peer to peer chat and VoIP software. The remote<br />

version of this software contains a security issue that may allow a local attacker to<br />

overwrite sensitive data files. Successful exploitation would result in loss of confidential<br />

data or possibly a Denial of Service (DoS).<br />

Solution: Upgrade to a version higher than 1.1.0.20.<br />

CVE Not available<br />

SSH IPSEC Express 1.1.0 VPN Detection<br />

<strong>PVS</strong> ID: 3071 FAMILY: Generic RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is running the IPSEC Express 1.1.0 VPN Server.\nA VPN (Virtual Private<br />

<strong>Network</strong>) allows remote users to connect to an internal network as if they were local users.<br />

A VPN that allows split-tunneling will essentially serve as a bridge between the remote<br />

network and the internal network. Special care should be taken to ensure that remote VPN<br />

clients connect securely and do not introduce an unacceptable level of risk to the internal<br />

computing environment.<br />

Solution: Ensure that the VPN is acceptable with respect to corporate guidelines and policies.<br />

CVE Not available<br />

SSH IPSEC Express 1.1.1 VPN Detection<br />

<strong>PVS</strong> ID: 3072 FAMILY: Generic RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is running the IPSEC Express 1.1.1 VPN Server.\nA VPN (Virtual Private<br />

<strong>Network</strong>) allows remote users to connect to an internal network as if they were local users.<br />

A VPN that allows split-tunneling will essentially serve as a bridge between the remote<br />

network and the internal network. Special care should be taken to ensure that remote VPN<br />

clients connect securely and do not introduce an unacceptable level of risk to the internal<br />

computing environment.<br />

Solution: Ensure that the VPN is acceptable with respect to corporate guidelines and policies.<br />

CVE Not available<br />

SSH IPSEC Express 1.1.2 VPN Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 3073 FAMILY: Generic RISK: LOW NESSUS ID:Not Available<br />

Family Internet Services 785

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!