vulnerability

Scanning Diagnostics: Unknown error while trying to access the remote SAM

Severity
1
CVSS
(AV:L/AC:H/Au:M/C:N/I:N/A:N)
Published
Nov 2, 2021
Added
Nov 2, 2021
Modified
Nov 2, 2021

Description


The following information is for Scan Diagnostic purposes only, and is not indicative of a detected vulnerability.



Security Account Manager (SAM) access is required for policy assessments but is not a requirement for vulnerability assessment.



The scanning user encountered an unknown error while attempting to verify remote access to the SAM service.



The scanning user requires remote access to the SAM to collect information about users and groups on the target system. This information is required for policy assessment.



Allowing SAM access over SMBv1 is a security concern as user information could be retrieved via packet inspection. SAM access should only be allowed over encrypted protocols.

Solution

rapid7-diagnostics-cifs-sam-unknown-error

References

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.