CoSoSys Endpoint Protector 4 Predictable Password

This script is Copyright (C) 2012 Tenable Network Security, Inc.


Synopsis :

Accounts on the remote host have easily predictable passwords.

Description :

The remote CoSoSys Endpoint Protector 4 is affected by a password
disclosure flaw.

Specifically, the 'epproot' account is set to the default password
'eroot!00($SUM)RO', where ($SUM) is the sum of the 9 digits in the
appliance serial number.

Solution :

Change the password for this account.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 7.1
(CVSS2#E:F/RL:U/RC:ND)
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 62942 ()

Bugtraq ID: 55570

CVE ID: CVE-2012-2994