Language:
Severity: High
ID: 26919
File Name: smb_guest_account.nasl
Version: 1.20
Type: remote
Agent: windows
Family: Windows
Published: 10/4/2007
Updated: 6/7/2024
Supported Sensors: Nessus
CVSS Score Rationale: Av:n is justified since the plugin tries to login via network services. nist specifies that the vulnerability pertains to a domain user. given that the plugin only tests for a guest account, which likely has limited permissions, the cia is partial instead of complete.
Risk Factor: Medium
Score: 6.7
Risk Factor: High
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS Score Source: CVE-1999-0505
CPE: cpe:/o:microsoft:windows
Required KB Items: SMB/guest_enabled
Excluded KB Items: Host/dead
Exploit Available: true
Exploit Ease: Exploits are available
Vulnerability Publication Date: 1/1/1999
Metasploit (Microsoft Windows Authenticated Powershell Command Execution)
CVE: CVE-1999-0505