PT-2018-10276 · Unknown · Emc Integrated Data Protection Appliance

Published

2018-11-02

·

Updated

2019-01-30

·

CVE-2018-11062

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Integrated Data Protection Appliance versions 2.0 through 2.2
Description The issue concerns undocumented accounts named support and admin that are protected with default passwords, allowing a malicious user with knowledge of these passwords to potentially log in to the system. These accounts have limited privileges, granting access to certain system files for read and write operations.
Recommendations For versions 2.0 through 2.2, change the default passwords of the support and admin accounts to secure passwords to prevent unauthorized access. As a temporary workaround, consider disabling the support and admin accounts until secure passwords are set. Restrict access to system files that can be accessed by these accounts to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11062

Affected Products

Emc Integrated Data Protection Appliance