vuln assesment 2

MoonSun20
MyBasicNetworkScan.pdf

Report generated by Nessus™

Expand All|Collapse All

My Basic Network Scan Wed, 08 Apr 2020 09:12:48 Pacific Standard Time

TABLE OF CONTENTS

Hosts Executive Summary

192.168.1.10

192.168.1.25

192.168.1.30

192.168.1.100

Hosts Executive Summary

192.168.1.10

0 1 1 0 22 CRITICAL HIGH MEDIUM LOW INFO

Severity CVSS Plugin Name

HIGH 9.3 97833 MS17-010: Security Update for Microsoft Windows SMB Server (4013389) (ETERNALBLUE) (ETERNALCHAMPION) (ETERNALROMANCE) (ETERNALSYNERGY) (WannaCry) (EternalRocks) (Petya) (uncredentialed check)

MEDIUM 5.0 57608 SMB Signing not required

INFO N/A 45590 Common Platform Enumeration (CPE)

INFO N/A 10736 DCE Services Enumeration

INFO N/A 54615 Device Type

INFO N/A 35716 Ethernet Card Manufacturer Detection

INFO N/A 86420 Ethernet MAC Addresses

INFO N/A 12053 Host Fully Qualified Domain Name (FQDN) Resolution

INFO N/A 117886 Local Checks Not Enabled (info)

INFO N/A 10394 Microsoft Windows SMB Log In Possible

INFO N/A 10785 Microsoft Windows SMB NativeLanManager Remote System Information Disclosure

INFO N/A 26917 Microsoft Windows SMB Registry : Nessus Cannot Access the Windows Registry

INFO N/A 11011 Microsoft Windows SMB Service Detection

INFO N/A 100871 Microsoft Windows SMB Versions Supported (remote check)

INFO N/A 106716 Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)

INFO N/A 11219 Nessus SYN scanner

Hide Details

INFO N/A 19506 Nessus Scan Information

INFO N/A 110723 No Credentials Provided

INFO N/A 11936 OS Identification

INFO N/A 96982 Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)

INFO N/A 25220 TCP/IP Timestamps Supported

INFO N/A 10287 Traceroute Information

INFO N/A 20094 VMware Virtual Machine Detection

INFO N/A 10150 Windows NetBIOS / SMB Remote Host Information Disclosure

192.168.1.25

0 1 2 2 43 CRITICAL HIGH MEDIUM LOW INFO

Severity CVSS Plugin Name

HIGH 7.5 42411 Microsoft Windows SMB Shares Unprivileged Access

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

LOW 2.6 70658 SSH Server CBC Mode Ciphers Enabled

LOW 2.6 71049 SSH Weak MAC Algorithms Enabled

INFO N/A 10114 ICMP Timestamp Request Remote Date Disclosure

INFO N/A 18261 Apache Banner Linux Distribution Disclosure

INFO N/A 48204 Apache HTTP Server Version

INFO N/A 39519 Backported Security Patch Detection (FTP)

INFO N/A 39520 Backported Security Patch Detection (SSH)

INFO N/A 39521 Backported Security Patch Detection (WWW)

INFO N/A 45590 Common Platform Enumeration (CPE)

INFO N/A 54615 Device Type

INFO N/A 35716 Ethernet Card Manufacturer Detection

INFO N/A 86420 Ethernet MAC Addresses

INFO N/A 10092 FTP Server Detection

INFO N/A 43111 HTTP Methods Allowed (per directory)

INFO N/A 10107 HTTP Server Type and Version

INFO N/A 24260 HyperText Transfer Protocol (HTTP) Information

INFO N/A 117886 Local Checks Not Enabled (info)

INFO N/A 17651 Microsoft Windows SMB : Obtains the Password Policy

INFO N/A 10394 Microsoft Windows SMB Log In Possible

INFO N/A 10859 Microsoft Windows SMB LsaQueryInformationPolicy Function SID Enumeration

INFO N/A 10785 Microsoft Windows SMB NativeLanManager Remote System Information Disclosure

INFO N/A 11011 Microsoft Windows SMB Service Detection

INFO N/A 60119 Microsoft Windows SMB Share Permissions Enumeration

INFO N/A 10395 Microsoft Windows SMB Shares Enumeration

INFO N/A 100871 Microsoft Windows SMB Versions Supported (remote check)

INFO N/A 106716 Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)

INFO N/A 11219 Nessus SYN scanner

INFO N/A 19506 Nessus Scan Information

INFO N/A 110723 No Credentials Provided

INFO N/A 11936 OS Identification

INFO N/A 10860 SMB Use Host SID to Enumerate Local Users

INFO N/A 70657 SSH Algorithms and Languages Supported

INFO N/A 10881 SSH Protocol Versions Supported

INFO N/A 10267 SSH Server Type and Version Information

INFO N/A 25240 Samba Server Detection

INFO N/A 104887 Samba Version

INFO N/A 96982 Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)

INFO N/A 22964 Service Detection

INFO N/A 25220 TCP/IP Timestamps Supported

INFO N/A 10287 Traceroute Information

INFO N/A 66293 Unix Operating System on Extended Support

INFO N/A 20094 VMware Virtual Machine Detection

INFO N/A 10150 Windows NetBIOS / SMB Remote Host Information Disclosure

INFO N/A 66717 mDNS Detection (Local Network)

INFO N/A 52703 vsftpd Detection

Hide Details

192.168.1.30

5 1 12 2 57 CRITICAL HIGH MEDIUM LOW INFO

Severity CVSS Plugin Name

CRITICAL 10.0 51988 Bind Shell Backdoor Detection

CRITICAL 10.0 32314 Debian OpenSSH/OpenSSL Package Random Number Generator Weakness

CRITICAL 10.0 32321 Debian OpenSSH/OpenSSL Package Random Number Generator Weakness (SSL check)

CRITICAL 10.0 11356 NFS Exported Share Information Disclosure

CRITICAL 10.0 33850 Unix Operating System Unsupported Version Detection

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 6.1 104743 TLS Version 1.0 Protocol Detection

MEDIUM 5.0 11213 HTTP TRACE / TRACK Methods Allowed

MEDIUM 5.0 42256 NFS Shares World Readable

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

MEDIUM 4.3 65821 SSL RC4 Cipher Suites Supported (Bar Mitzvah)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

LOW 2.6 70658 SSH Server CBC Mode Ciphers Enabled

LOW 2.6 71049 SSH Weak MAC Algorithms Enabled

INFO N/A 10114 ICMP Timestamp Request Remote Date Disclosure

INFO N/A 10223 RPC portmapper Service Detection

INFO N/A 21186 AJP Connector Detection

INFO N/A 18261 Apache Banner Linux Distribution Disclosure

INFO N/A 48204 Apache HTTP Server Version

INFO N/A 84574 Backported Security Patch Detection (PHP)

INFO N/A 39520 Backported Security Patch Detection (SSH)

INFO N/A 39521 Backported Security Patch Detection (WWW)

INFO N/A 45590 Common Platform Enumeration (CPE)

INFO N/A 10028 DNS Server BIND version Directive Remote Version Detection

INFO N/A 11002 DNS Server Detection

INFO N/A 72779 DNS Server Version Detection

INFO N/A 35371 DNS Server hostname.bind Map Hostname Disclosure

INFO N/A 54615 Device Type

INFO N/A 35716 Ethernet Card Manufacturer Detection

INFO N/A 86420 Ethernet MAC Addresses

INFO N/A 10092 FTP Server Detection

INFO N/A 10107 HTTP Server Type and Version

INFO N/A 24260 HyperText Transfer Protocol (HTTP) Information

INFO N/A 11156 IRC Daemon Version Detection

INFO N/A 117886 Local Checks Not Enabled (info)

INFO N/A 11011 Microsoft Windows SMB Service Detection

INFO N/A 106716 Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)

INFO N/A 10437 NFS Share Export List

INFO N/A 11219 Nessus SYN scanner

INFO N/A 19506 Nessus Scan Information

INFO N/A 110723 No Credentials Provided

INFO N/A 11936 OS Identification

INFO N/A 50845 OpenSSL Detection

INFO N/A 48243 PHP Version Detection

INFO N/A 118224 PostgreSQL STARTTLS Support

INFO N/A 26024 PostgreSQL Server Detection

INFO N/A 22227 RMI Registry Detection

INFO N/A 11111 RPC Services Enumeration

INFO N/A 53335 RPC portmapper (TCP)

INFO N/A 10263 SMTP Server Detection

Hide Details

INFO N/A 70657 SSH Algorithms and Languages Supported

INFO N/A 10881 SSH Protocol Versions Supported

INFO N/A 10267 SSH Server Type and Version Information

INFO N/A 56984 SSL / TLS Versions Supported

INFO N/A 45410 SSL Certificate 'commonName' Mismatch

INFO N/A 10863 SSL Certificate Information

INFO N/A 70544 SSL Cipher Block Chaining Cipher Suites Supported

INFO N/A 21643 SSL Cipher Suites Supported

INFO N/A 62563 SSL Compression Methods Supported

INFO N/A 57041 SSL Perfect Forward Secrecy Cipher Suites Supported

INFO N/A 22964 Service Detection

INFO N/A 17975 Service Detection (GET request)

INFO N/A 11153 Service Detection (HELP Request)

INFO N/A 25220 TCP/IP Timestamps Supported

INFO N/A 11819 TFTP Daemon Detection

INFO N/A 10287 Traceroute Information

INFO N/A 11154 Unknown Service Detection: Banner Retrieval

INFO N/A 20094 VMware Virtual Machine Detection

INFO N/A 11424 WebDAV Detection

INFO N/A 10150 Windows NetBIOS / SMB Remote Host Information Disclosure

INFO N/A 52703 vsftpd Detection

192.168.1.100

0 0 1 0 26 CRITICAL HIGH MEDIUM LOW INFO

Severity CVSS Plugin Name

MEDIUM 5.0 57608 SMB Signing not required

INFO N/A 45590 Common Platform Enumeration (CPE)

INFO N/A 10736 DCE Services Enumeration

INFO N/A 54615 Device Type

Hide Details

INFO N/A 35716 Ethernet Card Manufacturer Detection

INFO N/A 86420 Ethernet MAC Addresses

INFO N/A 10092 FTP Server Detection

INFO N/A 43111 HTTP Methods Allowed (per directory)

INFO N/A 10107 HTTP Server Type and Version

INFO N/A 12053 Host Fully Qualified Domain Name (FQDN) Resolution

INFO N/A 24260 HyperText Transfer Protocol (HTTP) Information

INFO N/A 117886 Local Checks Not Enabled (info)

INFO N/A 10785 Microsoft Windows SMB NativeLanManager Remote System Information Disclosure

INFO N/A 11011 Microsoft Windows SMB Service Detection

INFO N/A 100871 Microsoft Windows SMB Versions Supported (remote check)

INFO N/A 106716 Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)

INFO N/A 11219 Nessus SYN scanner

INFO N/A 19506 Nessus Scan Information

INFO N/A 110723 No Credentials Provided

INFO N/A 11936 OS Identification

INFO N/A 96982 Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)

INFO N/A 22964 Service Detection

INFO N/A 25220 TCP/IP Timestamps Supported

INFO N/A 10287 Traceroute Information

INFO N/A 20094 VMware Virtual Machine Detection

INFO N/A 11422 Web Server Unconfigured - Default Install Page Present

INFO N/A 10150 Windows NetBIOS / SMB Remote Host Information Disclosure

© 2020 Tenable™, Inc. All rights reserved.