Alcatel OmniPCX Default Passwords Vulnerability
BID:4127
Info
Alcatel OmniPCX Default Passwords Vulnerability
| Bugtraq ID: | 4127 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 19 2002 12:00AM |
| Updated: | Feb 19 2002 12:00AM |
| Credit: | This vulnerability was announced in a Security Bugware Advisory on February 19, 2002. |
| Vulnerable: |
Alcatel-Lucent OmniPCX 4400 0 |
| Not Vulnerable: | |
Discussion
Alcatel OmniPCX Default Passwords Vulnerability
OmniPCX is an enterprise-level Personal Communications Exchange (PCX) system maintained and distributed by Alcatel.
OmniPCX systems do not prompt users to change passwords of various accounts during install. The passwords used for various accounts on the PCX system are known defaults. This problem is further compounded by the fact that a number of services, such as telnet, ftp, and login listen on the system by default. This problem is known to affect OmniPCX 4400 systems, and may affect others as well.
The known passwords are as follows:
llatsni (install)
tlah (halt)
dhs3pms (dhs3pms)
adfexc (adfexc)
client (client)
kermit (kermit)
dhs3mt (dhs3mt)
at4400 (at4400)
mtch (mtch)
mtcl (mtcl)
letacla (root)
OmniPCX is an enterprise-level Personal Communications Exchange (PCX) system maintained and distributed by Alcatel.
OmniPCX systems do not prompt users to change passwords of various accounts during install. The passwords used for various accounts on the PCX system are known defaults. This problem is further compounded by the fact that a number of services, such as telnet, ftp, and login listen on the system by default. This problem is known to affect OmniPCX 4400 systems, and may affect others as well.
The known passwords are as follows:
llatsni (install)
tlah (halt)
dhs3pms (dhs3pms)
adfexc (adfexc)
client (client)
kermit (kermit)
dhs3mt (dhs3mt)
at4400 (at4400)
mtch (mtch)
mtcl (mtcl)
letacla (root)
Solution / Fix
Alcatel OmniPCX Default Passwords Vulnerability
Solution:
The discoverers' of this vulnerability have made it known that Alcatel Support does not advise the changing of the default passwords.
---
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The discoverers' of this vulnerability have made it known that Alcatel Support does not advise the changing of the default passwords.
---
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.