SonicWALL ViewPoint Server Default Credentials

high Nessus Plugin ID 56649

Synopsis

The remote web application uses default credentials.

Description

It is possible to log into SonicWALL ViewPoint Server by providing the default admin credentials. A remote attacker could exploit this to gain administrative control of the application.

Solution

Secure the admin account with a strong password.

See Also

http://www.sonicwall.com/lat/488_3036.html

Plugin Details

Severity: High

ID: 56649

File Name: sonicwall_viewpoint_default_creds.nasl

Version: 1.8

Type: remote

Family: CGI abuses

Published: 10/26/2011

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: x-cpe:/a:sonicwall:viewpoint_server

Required KB Items: www/sonicwall_viewpoint

Excluded KB Items: global_settings/supplied_logins_only