Adobe Document Server Default Credentials

high Nessus Plugin ID 21099

Synopsis

The administration console for the remote web server is protected with default credentials.

Description

The remote host is running Adobe Document Server, a server that dynamically creates and manipulates PDF documents as well as graphic images.

The installation of Adobe Document Server on the remote host uses the default username and password to control access to its administrative console. Knowing these, an attacker can gain control of the affected application.

Solution

Login via the administration interface and change the password for the admin account.

Plugin Details

Severity: High

ID: 21099

File Name: adobe_document_server_default_creds.nasl

Version: 1.19

Type: remote

Family: CGI abuses

Published: 3/18/2006

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:adobe:document_server

Excluded KB Items: global_settings/supplied_logins_only