HP OpenView Client Configuration Manager Default Credentials

high Nessus Plugin ID 27802

Synopsis

The remote web service is protected with default credentials.

Description

The remote host is running HP OpenView Client Configuration Manager (OVCCM), a PC software configuration management application.

The remote installation of OVCCM is configured to use default credentials to control access. Knowing these, an attacker can gain control of the affected application.

Solution

Change the password for the 'admin' account by logging into OVCCM, navigating to 'Configuration / Console Access', and editing the 'admin' account.

Plugin Details

Severity: High

ID: 27802

File Name: ovccm_default_creds.nasl

Version: 1.16

Type: remote

Family: CGI abuses

Published: 11/7/2007

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

Excluded KB Items: global_settings/supplied_logins_only