Microsoft SQL Server UDP Query Remote Version Disclosure

info Nessus Plugin ID 10674

Synopsis

It is possible to determine the remote SQL server version.

Description

Microsoft SQL server has a function wherein remote users can query the database server for the version that is being run. The query takes place over the same UDP port that handles the mapping of multiple SQL server instances on the same machine.

It is important to note that, after Version 8.00.194, Microsoft decided not to update this function. This means that the data returned by the SQL ping is inaccurate for newer releases of SQL Server.

Solution

If there is only a single SQL instance installed on the remote host, consider filter incoming traffic to this port.

Plugin Details

Severity: Info

ID: 10674

File Name: mssql_ping.nasl

Version: 1.29

Type: remote

Family: Databases

Published: 5/25/2001

Updated: 3/13/2018

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/a:microsoft:sql_server