Gateway GS-400 Server Default Administrator Password Vulnerability
BID:5472
Info
Gateway GS-400 Server Default Administrator Password Vulnerability
| Bugtraq ID: | 5472 |
| Class: | Design Error |
| CVE: |
CVE-2002-1440 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Vulnerability discovery credited to Keith T. Morgan <[email protected]>. |
| Vulnerable: |
Gateway GS-400 0 |
| Not Vulnerable: | |
Discussion
Gateway GS-400 Server Default Administrator Password Vulnerability
The GS-400 is a storage machine distributed by Gateway.
A default vendor password of "0001n" is used on all GS-400 servers. This password is unchangeable via the administrative interface. This could allow an attacker with the ability to remotely connect to the server to gain unauthorized access.
The GS-400 is a storage machine distributed by Gateway.
A default vendor password of "0001n" is used on all GS-400 servers. This password is unchangeable via the administrative interface. This could allow an attacker with the ability to remotely connect to the server to gain unauthorized access.
Exploit / POC
Gateway GS-400 Server Default Administrator Password Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gateway GS-400 Server Default Administrator Password Vulnerability
Solution:
It has been reported that Gateway will not be fixing this issue, and has advised customers that they may return affected devices.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that Gateway will not be fixing this issue, and has advised customers that they may return affected devices.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Gateway GS-400 Server Default Administrator Password Vulnerability
References:
References: