FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://bugs.freenas.org/issues/5844 | issue tracking third party advisory |
http://www.securityfocus.com/bid/69249 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2014/08/19/2 | third party advisory mailing list |