EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain potentially sensitive information via a login session.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/131250/EMC-PowerPath-Virtual-Appliance-Undocumented-User-Accounts.html | vdb entry third party advisory |
http://seclists.org/bugtraq/2015/Apr/1 | mailing list vdb entry third party advisory |