PostgreSQL Default Unpassworded Account

This script is Copyright (C) 2000-2015 Tenable Network Security, Inc.

Synopsis :

The remote database server can be accessed without a password.

Description :

It is possible to connect to the remote PostgreSQL database server
using an unpassworded account. This may allow an attacker to launch
further attacks against the database.

Solution :

Log into this host and set a password for any affected accounts using
the 'ALTER USER' command.

In addition, configure the service by editing the file 'pg_hba.conf'
to require a password (or Kerberos) authentication for all remote
hosts that have legitimate access to this service and to require a
password locally using the line 'local all password'.

Risk factor :

High / CVSS Base Score : 7.5
Public Exploit Available : true

Family: Databases

Nessus Plugin ID: 10483 ()

Bugtraq ID:

CVE ID: CVE-1999-0508

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now