Auerswald COMsuite CTI Application Weak Default Password Vulnerability
BID:7458
Info
Auerswald COMsuite CTI Application Weak Default Password Vulnerability
| Bugtraq ID: | 7458 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2003 12:00AM |
| Updated: | Apr 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Pierre Kroma <[email protected]>. |
| Vulnerable: |
Auerswald COMsuite 3.1 06/2001 |
| Not Vulnerable: | |
Discussion
Auerswald COMsuite CTI Application Weak Default Password Vulnerability
Auerswald COMsuite CTI application has been reported prone to weak default password vulnerability.
It has been reported that, when installed, the CTI control center creates a user to enable operating system interaction. The password for this user account is easily guessed using readily available tools.
Once the password is retrieved the "runasositron" account can be used locally and remotely to access the Windows PC on which COMsuite is installed.
Auerswald COMsuite CTI application has been reported prone to weak default password vulnerability.
It has been reported that, when installed, the CTI control center creates a user to enable operating system interaction. The password for this user account is easily guessed using readily available tools.
Once the password is retrieved the "runasositron" account can be used locally and remotely to access the Windows PC on which COMsuite is installed.
Exploit / POC
Auerswald COMsuite CTI Application Weak Default Password Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Auerswald COMsuite CTI Application Weak Default Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Auerswald COMsuite CTI Application Weak Default Password Vulnerability
References:
References:
- COMsuite Homepage (Auerswald)
- Auerswald COMsuite/ Back Door (Kroma Pierre
)