By default, GEMS Server installs an undocumented remotely accessible account with no password. This allows attackers to trivially access the program or system.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Solution:
Change Default Setting
OSVDB:
Backdoor
Solution
Immediately after installation, change (create a) password to a unique and secure password for the undocumented account.