ID

VAR-201102-0205


CVE

CVE-2011-0330


TITLE

DellSystemLite.ocx of Dell DellSystemLite.Scanner ActiveX Any in control WQL Statement execution vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2011-004087

DESCRIPTION

The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of information about installed software. The DellSystemLite.Scanner ActiveX control is prone to a directory-traversal vulnerability and an information-disclosure vulnerability because the application fails to sufficiently sanitize user-supplied input. Exploiting these issues may allow an attacker to obtain sensitive information. DellSystemLite.ocx 1.0.0.0 is vulnerable; other versions may also be affected. Dell The DellSystemLite.Scanner control is a scanner control. ---------------------------------------------------------------------- Get a tax break on purchases of Secunia Solutions! If you are a U.S. company, you may be qualified for a tax break for your software purchases. Learn more at: http://secunia.com/products/corporate/vim/section_179/ ---------------------------------------------------------------------- TITLE: Dell DellSystemLite.Scanner ActiveX Control Two Vulnerabilities SECUNIA ADVISORY ID: SA42880 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/42880/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=42880 RELEASE DATE: 2011-02-18 DISCUSS ADVISORY: http://secunia.com/advisories/42880/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/42880/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=42880 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Secunia Research has discovered two vulnerabilities in Dell DellSystemLite.Scanner ActiveX control, which can be exploited by malicious people to disclose various information. 1) An input validation error in the "GetData()" method can be exploited to disclose the contents of arbitrary text files via directory traversal specifiers passed in the "fileID" parameter. 2) The unsafe property "WMIAttributesOfInterest" allows assigning arbitrary WMI Query Language (WQL) statements and can be exploited to e.g. disclose system information like installed software. The vulnerabilities are confirmed in DellSystemLite.ocx version 1.0.0.0. SOLUTION: Set the kill-bit for the affected ActiveX control. PROVIDED AND/OR DISCOVERED BY: Dmitriy Pletnev, Secunia Research. ORIGINAL ADVISORY: Secunia Research: http://secunia.com/secunia_research/2011-10/ http://secunia.com/secunia_research/2011-11/ OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXPLOIT: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.07

sources: NVD: CVE-2011-0330 // JVNDB: JVNDB-2011-004087 // BID: 46443 // VULHUB: VHN-48275 // PACKETSTORM: 98579

AFFECTED PRODUCTS

vendor:dellmodel:dellsystemlite.scanner activex controlscope:eqversion:1.0.0.0

Trust: 2.4

vendor:dellmodel:dellsystemlite.ocxscope:eqversion:1.0.0.0

Trust: 0.3

sources: BID: 46443 // JVNDB: JVNDB-2011-004087 // CNNVD: CNNVD-201102-296 // NVD: CVE-2011-0330

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-0330
value: MEDIUM

Trust: 1.0

NVD: CVE-2011-0330
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201102-296
value: MEDIUM

Trust: 0.6

VULHUB: VHN-48275
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2011-0330
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-48275
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-48275 // JVNDB: JVNDB-2011-004087 // CNNVD: CNNVD-201102-296 // NVD: CVE-2011-0330

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-48275 // JVNDB: JVNDB-2011-004087 // NVD: CVE-2011-0330

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201102-296

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201102-296

CONFIGURATIONS

sources: JVNDB: JVNDB-2011-004087

PATCH

title:Top pageurl:http://www.dell.com/

Trust: 0.8

sources: JVNDB: JVNDB-2011-004087

EXTERNAL IDS

db:NVDid:CVE-2011-0330

Trust: 2.8

db:BIDid:46443

Trust: 2.0

db:SECUNIAid:42880

Trust: 1.8

db:SECTRACKid:1025094

Trust: 1.1

db:JVNDBid:JVNDB-2011-004087

Trust: 0.8

db:CNNVDid:CNNVD-201102-296

Trust: 0.7

db:NSFOCUSid:16473

Trust: 0.6

db:VULHUBid:VHN-48275

Trust: 0.1

db:PACKETSTORMid:98579

Trust: 0.1

sources: VULHUB: VHN-48275 // BID: 46443 // JVNDB: JVNDB-2011-004087 // PACKETSTORM: 98579 // CNNVD: CNNVD-201102-296 // NVD: CVE-2011-0330

REFERENCES

url:http://secunia.com/secunia_research/2011-11/

Trust: 2.1

url:http://www.securityfocus.com/bid/46443

Trust: 1.7

url:http://secunia.com/advisories/42880

Trust: 1.7

url:http://www.securitytracker.com/id?1025094

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-0330

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-0330

Trust: 0.8

url:http://www.nsfocus.net/vulndb/16473

Trust: 0.6

url:http://secunia.com/secunia_research/2011-10/

Trust: 0.4

url:http://www.dell.com/

Trust: 0.3

url:http://secunia.com/products/corporate/evm/

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=42880

Trust: 0.1

url:http://secunia.com/products/corporate/vim/section_179/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/advisories/42880/#comments

Trust: 0.1

url:http://secunia.com/advisories/42880/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: VULHUB: VHN-48275 // BID: 46443 // JVNDB: JVNDB-2011-004087 // PACKETSTORM: 98579 // CNNVD: CNNVD-201102-296 // NVD: CVE-2011-0330

CREDITS

Dmitriy Pletnev of Secunia Research.

Trust: 0.3

sources: BID: 46443

SOURCES

db:VULHUBid:VHN-48275
db:BIDid:46443
db:JVNDBid:JVNDB-2011-004087
db:PACKETSTORMid:98579
db:CNNVDid:CNNVD-201102-296
db:NVDid:CVE-2011-0330

LAST UPDATE DATE

2025-04-11T22:54:03.865000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-48275date:2011-03-18T00:00:00
db:BIDid:46443date:2011-02-18T00:00:00
db:JVNDBid:JVNDB-2011-004087date:2012-03-27T00:00:00
db:CNNVDid:CNNVD-201102-296date:2011-02-23T00:00:00
db:NVDid:CVE-2011-0330date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-48275date:2011-02-21T00:00:00
db:BIDid:46443date:2011-02-18T00:00:00
db:JVNDBid:JVNDB-2011-004087date:2012-03-27T00:00:00
db:PACKETSTORMid:98579date:2011-02-18T03:41:40
db:CNNVDid:CNNVD-201102-296date:2011-02-23T00:00:00
db:NVDid:CVE-2011-0330date:2011-02-21T18:00:01.223