Overview
Some versions of the Multi-Tech ProxyServer products ship without a default password for the administrative interface.
Description
Some versions of the Multi-Tech ProxyServer products ships without a default password for the administrative interface permitting unauthenticated access via TELNET and HTTP. The administrative interface, or "supervisor" account, allows users to modify configuration settings on the ProxyServer device. At least the following versions of the ProxyServer products exhibit this condition:
|
Impact
This vulnerability is the result of weak authentication and access control policies and can result in one or more of the following impacts: unauthorized access, unauthorized monitoring, information leakage, denial of service, and permanent disability of affected devices. |
Solution
Supply an administrative password when the device is installed. According to Multi-Tech: |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | N/A | N/A |
Temporal | N/A | N/A |
Environmental | N/A |
References
Acknowledgements
Thanks to UkR-XblP
This document was written by Chad R Dougherty.
Other Information
CVE IDs: | None |
Severity Metric: | 3.71 |
Date Public: | 2002-12-13 |
Date First Published: | 2003-03-24 |
Date Last Updated: | 2007-04-26 12:51 UTC |
Document Revision: | 11 |