Arkeia Server Blank Default Root Password Vulnerability
BID:3203
Info
Arkeia Server Blank Default Root Password Vulnerability
| Bugtraq ID: | 3203 |
| Class: | Configuration Error |
| CVE: |
CVE-2001-0968 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 17 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced to Bugtraq by <[email protected]> on August 17, 2001. |
| Vulnerable: |
Knox Software Arkeia Server 4.2.8 -2 Knox Software Arkeia 5.3 Knox Software Arkeia 5.2 Knox Software Arkeia 4.2 Knox Software Arkeia 4.1 Knox Software Arkeia 4.0 |
| Not Vulnerable: | |
Discussion
Arkeia Server Blank Default Root Password Vulnerability
Arkeia Server is an enterprise-based backup software solution distributed and maintained by Knox Software.
The Arkeia Server software packages does not set the root password by default. If the software package is installed on an insecure network, this makes it possible for a remote user with an Arkeia client to gain access to the Arkeia server before the password is set by the administrator, and log in as root.
Arkeia Server is an enterprise-based backup software solution distributed and maintained by Knox Software.
The Arkeia Server software packages does not set the root password by default. If the software package is installed on an insecure network, this makes it possible for a remote user with an Arkeia client to gain access to the Arkeia server before the password is set by the administrator, and log in as root.
Exploit / POC
Arkeia Server Blank Default Root Password Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
References
Arkeia Server Blank Default Root Password Vulnerability
References:
References:
- Arkeia Possible remote root & information leakage (Maciej Bogucki
)