The following information is for Scan Diagnostic purposes only, and is not indicative of a detected vulnerability.
Security Account Manager (SAM) access is required for policy assessments but is not a requirement for vulnerability assessment.
The scanning user encountered access denied errors while attempting to remotely access the SAM service.
The scanning user requires remote access to the SAM to collect information about users and groups on the target system. This information is required for policy assessment.
Allowing SAM access over unencrypted connections is a security concern as user information could be retrieved via packet inspection. SAM access should only be allowed over encrypted protocols.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center