ASG-Sentry CGI Default Credentials

high Nessus Plugin ID 34395

Synopsis

The remote web application is protected with default credentials.

Description

The remote ASG-Sentry CGI script is configured to use default credentials to control administrative access. Knowing these, an attacker can gain administrative control of the affected application.

Solution

Change the password for the 'admin' account.

Plugin Details

Severity: High

ID: 34395

File Name: asg_sentry_cgi_default_creds.nasl

Version: 1.14

Type: remote

Family: CGI abuses

Published: 10/14/2008

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

Excluded KB Items: global_settings/supplied_logins_only