Nortel Multiple Default Accounts

high Nessus Plugin ID 15715

Synopsis

It is possible to log into the remote switch using default credentials.

Description

It is possible to log into the remote host by using a default set of credentials. An attacker may use these to gain access to the remote host.

These credentials are commonly found on Nortel Accelar routing switches.

Solution

Set a strong password for these accounts.

Plugin Details

Severity: High

ID: 15715

File Name: nortel_default_username_password.nasl

Version: 1.26

Type: remote

Family: Misc.

Published: 11/13/2004

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:H/RL:X/RC:X

Vulnerability Information

Excluded KB Items: global_settings/supplied_logins_only, login/unix/auth/broken, login/auth/broken