Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.
Weaknesses in this category are related to the management of credentials.
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.