Computer Associates ARCServe Cleartext Administrative Password Vulnerability
BID:3343
Info
Computer Associates ARCServe Cleartext Administrative Password Vulnerability
| Bugtraq ID: | 3343 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2001 12:00AM |
| Updated: | Sep 16 2001 12:00AM |
| Credit: | Reported to bugtraq by ron <[email protected]> on September 16, 2001. |
| Vulnerable: |
Computer Associates ARCServe 2000 Advanced Edition 7.0 Computer Associates ARCServe 2000 Computer Associates ARCServe 6.61 |
| Not Vulnerable: | |
Discussion
Computer Associates ARCServe Cleartext Administrative Password Vulnerability
ARCServe is an enterprise data backup and recovery solution from Computer Associates.
ARCServe stores its administrator account and password in cleartext.
Since ARCServe normally runs under an account with access to system files (or even that of the NT domain administrator), users able to read this information can gain administrative access to the host.
ARCServe is an enterprise data backup and recovery solution from Computer Associates.
ARCServe stores its administrator account and password in cleartext.
Since ARCServe normally runs under an account with access to system files (or even that of the NT domain administrator), users able to read this information can gain administrative access to the host.
Exploit / POC
Computer Associates ARCServe Cleartext Administrative Password Vulnerability
No exploit required for this vulnerability.
No exploit required for this vulnerability.
Solution / Fix
Computer Associates ARCServe Cleartext Administrative Password Vulnerability
Solution:
Limit access to the ARCSERVE$ network share to the backup account and domain administrator.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Limit access to the ARCSERVE$ network share to the backup account and domain administrator.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Computer Associates ARCServe Cleartext Administrative Password Vulnerability
References:
References: