Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

BrightStor ARCserve/Enterprise Backup Default Account

Critical

Synopsis

The remote host is configured with default or easily-guessed credentials.

Description

The remote host is running UniversalAgent, an agent used by BrightStor ARCserve to perform backups. The remote version of this agent contains a default account with the username '\x02root\x03' and password '\x02<%j8U]`~+Ri\x03'. An attacker may use this account to gain full access to the remote host.

Solution

Upgrade or patch according to vendor recommendations.