ACC's Tigris Access Terminal Vulnerability
BID:183
Info
ACC's Tigris Access Terminal Vulnerability
| Bugtraq ID: | 183 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Jan 03 1999 12:00AM |
| Updated: | Jan 03 1999 12:00AM |
| Credit: | This vulnerability was reported to the Bugtraq mailing list by Robert Thomas ([email protected]) on Jan. 3, 1999. |
| Vulnerable: |
ACC Tigris 10.5.8 |
| Not Vulnerable: | |
Discussion
ACC's Tigris Access Terminal Vulnerability
Tigris Terminal Servers are easily accessible with a default username and password of 'public'.
In addition, at login prompt an attacker can press Ctrl-U (or simply backspace the line) and type in any command (such as 'show') to display currently running configuration.
This kind of vulnerability is significant as it allows any remote attacker to gain crittical configuration information about your terminal servers.
Tigris Terminal Servers are easily accessible with a default username and password of 'public'.
In addition, at login prompt an attacker can press Ctrl-U (or simply backspace the line) and type in any command (such as 'show') to display currently running configuration.
This kind of vulnerability is significant as it allows any remote attacker to gain crittical configuration information about your terminal servers.
Exploit / POC
ACC's Tigris Access Terminal Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].