EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain potentially sensitive information via a login session.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/131250/EMC-PowerPath-Virtual-Appliance-Undocumented-User-Accounts.html | Third Party Advisory VDB Entry |
http://seclists.org/bugtraq/2015/Apr/1 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2015-04-05 01:59
Updated : 2024-02-04 18:35
NVD link : CVE-2015-0529
Mitre link : CVE-2015-0529
CVE.ORG link : CVE-2015-0529
JSON object : View
Products Affected
emc
- powerpath_virtual_appliance
CWE
CWE-255
Credentials Management Errors