751 : User Account Policy Password Cannot Be Changed
Printer | http://osvdb.org/751 | Email This | Edit Vulnerability

Views This Week

4

Views All Time

55

Info

Last Modified

4 months ago

Percent Complete

90%

Disclosure

Unknown

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Some systems may have an account policy that does not allow a user to change their password. This may be due to poor configuration or even as a result of an overzealous security posture. User accounts that do not allow password changes may pose a higher risk to an organization. If such an account has the password compromised for whatever reason, the user is unable to change the password once the disclosure is discovered. This may give an attacker an increased window to login to the account before an administrator can change the password.

Classification

Location: Local Access Required, Remote/Network Access Required
Attack Type: Authentication Management
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified
OSVDB: Best Practice

Solution

Administrators should maintain a strong user account policy which includes the ability for users to modify their own password. Such password changes should conform to a strong password policy. It is typically recommended that passwords are changed at least every 90 days.

Products

All Vendors
Watch-list
All Products
Watch-list
All Versions

References

Tools & Filters

Nessus

10912

Credit

Unknown or Incomplete

Blogs

None found at this time

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use