Default Password (sq!us3r) for 'dbadmin' Account

This script is Copyright (C) 2009-2011 Tenable Network Security, Inc.


Synopsis :

The remote system can be accessed with a default account.

Description :

The account 'dbadmin' on the remote host has the password 'sq!us3r'.

An attacker may leverage this issue to gain access to the affected
system.

Note that RioRey RIOS appliances, used for dynamic denial of service
mitigation, are reported to use these credentials to support
connections from rVIEW, the vendor's central management and
configuration tool, and that an attacker reportedly may be able to
escalate privileges through several vulnerabilities to gain full
control over the device.

See also :

http://packetstormsecurity.org/0910-exploits/riorey-passwd.txt

Solution :

If the affected device is a RioRey platform, contact the vendor for a
patch.

Otherwise, change the password for this account or disable it.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: Default Unix Accounts

Nessus Plugin ID: 42147 (account_dbadmin_squs3r.nasl)

Bugtraq ID: 42349

CVE ID: CVE-2009-3710