The remote host is affected by an authentication bypass vulnerability.
The remote host is affected by an authentication bypass vulnerability. A local attacker or a remote attacker with credentials for a standard user account has the ability to blank out the root account password. This can allow an authenticated attacker to escalate privileges to root and execute commands and read files as a system administrator. A remote attacker without credentials can set passwords on certain disabled accounts. Note that if this plugin is successful, Nessus has set the password on the 'nobody' account to 'nessus', and you will need to reset this password/re-disable this account to clean up.