PT-2015-4286 · Microsoft+3 · Windows+3

Stefan Viehböck

·

Publicado

2015-01-08

·

Atualizado

2015-01-08

·

CVE-2014-9576

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions VDG Security SENSE (formerly DIVA) version 2.3.13
Description The issue allows remote attackers to obtain access due to hardcoded passwords for certain accounts. Specifically, the passwords ArpaRomaWi for the root Postgres account, and !DVService for the postgres and NTP Windows user accounts are hardcoded.
Recommendations For VDG Security SENSE (formerly DIVA) version 2.3.13, consider changing the hardcoded passwords ArpaRomaWi and !DVService for the root Postgres, postgres, and NTP Windows user accounts to unique, secure passwords to prevent unauthorized access.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9576

Produtos afetados

Ntp
Postgres
Vdg Security Sense
Windows