PostgreSQL Default Unpassworded Account

This script is Copyright (C) 2000-2014 Tenable Network Security, Inc.


Synopsis :

The remote database server can be accessed without a password.

Description :

It is possible to connect to the remote PostgreSQL database server
using an unpassworded account. This may allow an attacker to launch
further attacks against the database.

Solution :

Log into this host and set a password for any affected accounts using
the 'ALTER USER' command.

In addition, configure the service by editing the file 'pg_hba.conf'
to require a password (or Kerberos) authentication for all remote
hosts that have legitimate access to this service and to require a
password locally using the line 'local all password'.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
Public Exploit Available : true

Family: Databases

Nessus Plugin ID: 10483 ()

Bugtraq ID:

CVE ID: CVE-1999-0508