{"api_version":"1","generated_at":"2026-07-23T09:27:21+00:00","cve":"CVE-2005-3786","urls":{"html":"https://cve.report/CVE-2005-3786","api":"https://cve.report/api/cve/CVE-2005-3786.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3786","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3786"},"summary":{"title":"CVE-2005-3786","description":"Novell ZENworks for Desktops 4.0.1, ZENworks for Servers 3.0.2, and ZENworks 6.5 Desktop Management does not restrict access to Remote Diagnostics, which allows local users to bypass security policies by using Console One.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-23 23:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/17700","name":"http://secunia.com/advisories/17700","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Novell ZENworks Remote-Diagnostics Access Control Weakness","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2544","name":"http://www.vupen.com/english/advisories/2005/2544","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015260","name":"http://securitytracker.com/id?1015260","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Novell ZENworks Console One Lets Remote Authenticated Users Access Diagnostic Functions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15540","name":"http://www.securityfocus.com/bid/15540","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Novell ZENworks Remote Diagnostics Console One Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098818.htm","name":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098818.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3786","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3786","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"zenworks","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"zenworks_desktops","cpe6":"4.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"zenworks_servers","cpe6":"3.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.206Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2005-2544","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2544"},{"name":"1015260","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015260"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098818.htm"},{"name":"17700","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17700"},{"name":"15540","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15540"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Novell ZENworks for Desktops 4.0.1, ZENworks for Servers 3.0.2, and ZENworks 6.5 Desktop Management does not restrict access to Remote Diagnostics, which allows local users to bypass security policies by using Console One."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-02-26T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2005-2544","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2544"},{"name":"1015260","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015260"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098818.htm"},{"name":"17700","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17700"},{"name":"15540","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15540"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3786","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Novell ZENworks for Desktops 4.0.1, ZENworks for Servers 3.0.2, and ZENworks 6.5 Desktop Management does not restrict access to Remote Diagnostics, which allows local users to bypass security policies by using Console One."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2005-2544","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2544"},{"name":"1015260","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015260"},{"name":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098818.htm","refsource":"CONFIRM","url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098818.htm"},{"name":"17700","refsource":"SECUNIA","url":"http://secunia.com/advisories/17700"},{"name":"15540","refsource":"BID","url":"http://www.securityfocus.com/bid/15540"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3786","datePublished":"2005-11-23T23:00:00.000Z","dateReserved":"2005-11-23T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.206Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-23 23:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:novell:zenworks:6.5:*:*:*:*:*:*:*","matchCriteriaId":"C4C0F6C2-8583-4CE7-A95C-59EB4C948F63"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:zenworks_desktops:4.0.1:*:*:*:*:*:*:*","matchCriteriaId":"D79D1539-0284-4861-852D-D07AD9A538F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:zenworks_servers:3.0.2:*:*:*:*:*:*:*","matchCriteriaId":"F7306E34-AFF4-40D8-BD03-F199FF5893C7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3786","Ordinal":"1","Title":"CVE-2005-3786","CVE":"CVE-2005-3786","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3786","Ordinal":"1","NoteData":"Novell ZENworks for Desktops 4.0.1, ZENworks for Servers 3.0.2, and ZENworks 6.5 Desktop Management does not restrict access to Remote Diagnostics, which allows local users to bypass security policies by using Console One.","Type":"Description","Title":"CVE-2005-3786"},{"CveYear":"2005","CveId":"3786","Ordinal":"2","NoteData":"2005-11-23","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3786","Ordinal":"3","NoteData":"2009-02-26","Type":"Other","Title":"Modified"}]}}}