Okena StormWatch Null Default Password Vulnerability
BID:6423
Info
Okena StormWatch Null Default Password Vulnerability
| Bugtraq ID: | 6423 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2002 12:00AM |
| Updated: | Dec 18 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to Marc Ruef <[email protected]>. |
| Vulnerable: |
Okena StormWatch |
| Not Vulnerable: | |
Discussion
Okena StormWatch Null Default Password Vulnerability
A vulnerability has been reported for Okena StormWatch's database server. Reportedly, the database administrative user is supplied with a blank password.
A remote attacker can exploit this vulnerability by connecting to a vulnerable system's StormWatch database server as an administrative user to corrupt database information. It may also be possible for attackers to gain access to the underlying device.
It is likely that this is or is related to the issue described in BID 4797.
** The vendor has responded stating that when StormWatch is installed, the 'sa' account password is set to a random value. As well, the authentication type is set to 'windows' to ensure that only a local administrator is able to access the database.
The vendor has stated that database access via ODBC, as the local windows administrator, without entering a password, is the expected behaviour of the database. This is because the database uses the local administrator credentials when access is required.
This BID will be retired and kept for archival purposes.
A vulnerability has been reported for Okena StormWatch's database server. Reportedly, the database administrative user is supplied with a blank password.
A remote attacker can exploit this vulnerability by connecting to a vulnerable system's StormWatch database server as an administrative user to corrupt database information. It may also be possible for attackers to gain access to the underlying device.
It is likely that this is or is related to the issue described in BID 4797.
** The vendor has responded stating that when StormWatch is installed, the 'sa' account password is set to a random value. As well, the authentication type is set to 'windows' to ensure that only a local administrator is able to access the database.
The vendor has stated that database access via ODBC, as the local windows administrator, without entering a password, is the expected behaviour of the database. This is because the database uses the local administrator credentials when access is required.
This BID will be retired and kept for archival purposes.
Exploit / POC
Okena StormWatch Null Default Password Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Okena StormWatch Null Default Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Okena StormWatch Null Default Password Vulnerability
References:
References:
- Okena Home Page (Okena)
- Missing admin sql password in Okena StormWatch (Marc Ruef
) - RE: Missing admin sql password in Okena StormWatch (Marcus Gavel
)