Symantec ON Command CCM Remote Database Default Password Vulnerability
BID:11225
Info
Symantec ON Command CCM Remote Database Default Password Vulnerability
| Bugtraq ID: | 11225 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2004 12:00AM |
| Updated: | Sep 21 2004 12:00AM |
| Credit: | Jonas Olsson <[email protected]> is responsible for disclosure of this issue. |
| Vulnerable: |
Symantec ON iCommand 3.0 Symantec ON Command CCM 5.4 Symantec ON Command CCM 5.3 Symantec ON Command CCM 5.2 Symantec ON Command CCM 5.1 Symantec ON Command CCM 5.0 |
| Not Vulnerable: | |
Discussion
Symantec ON Command CCM Remote Database Default Password Vulnerability
Reportedly Symantec ON Command CCM is affected by a remote default password vulnerability in the underlying database. This issue is due to a design error in the application that provides a number of default usernames and passwords, some of which cannot be changed.
A attacker may exploit these issues to gain full access to the underlying database. This will allow attackers to view plaintext user credentials as well as other sensitive data.
Reportedly Symantec ON Command CCM is affected by a remote default password vulnerability in the underlying database. This issue is due to a design error in the application that provides a number of default usernames and passwords, some of which cannot be changed.
A attacker may exploit these issues to gain full access to the underlying database. This will allow attackers to view plaintext user credentials as well as other sensitive data.
Exploit / POC
Symantec ON Command CCM Remote Database Default Password Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Symantec ON Command CCM Remote Database Default Password Vulnerability
Solution:
Symantec has released an advisory (SYM04-014) along with patches dealing with this issue. Customers are advised to visit http://www.symantec.com/techsupp to acquire the appropriate patch. Please see the referenced advisory for more information.
Solution:
Symantec has released an advisory (SYM04-014) along with patches dealing with this issue. Customers are advised to visit http://www.symantec.com/techsupp to acquire the appropriate patch. Please see the referenced advisory for more information.
References
Symantec ON Command CCM Remote Database Default Password Vulnerability
References:
References:
- ON Command CCM Home Page (Symantec)
- Default username/password pairs in ON Command CCM 5.x database backend (Jonas Olsson
) - Re: Default username/password pairs in ON Command CCM 5.x database backend (Sym Security
)