OSVDB ID: 11308

Title: Compaq Insight Agent with BMC Patrol PFCUser Default Account

Info

Disclosure

Aug 17, 1999

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

By default, Compaq BMC component installs with a default password. The "PFCUser" account has a password of "240653C9467E45" which is publicly known and documented. This allows attackers to trivially access the program or system.

Classification

Location: Remote/Network Access Required, Local / Remote
Attack Type: Authentication Management
Impact: Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s): 1. Login as Administrator 2. Start a DOS Command Prompt Window 3. Change directory to %PFC_HOME% (CD /Winnt/System32/pfc) 4. Run the pfimuser program to change the password (Type pfimuser) 5. Type Username when prompted (PFCUser) 6. Type new password when prompted 7. Verify new password when prompted

Products

Hewlett-Packard Development Company, L.P.

Compaq Insight Management Agent

4.23

Management Agents for Servers

4.40

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218