Executive brief
A Unix-based operating system is configured with an account that has a default, blank, or missing password. This allows an unauthorized person to log into the system remotely, potentially gaining access to sensitive data or disrupting operations. This is a fundamental security configuration error that can lead to full system compromise.
Technical details
This vulnerability stems from insecure default configurations or administrative oversight where a Unix user account is left with a null, blank, or well-known default password. An attacker can exploit this by attempting to authenticate via network services (such as Telnet, SSH, or FTP) using common default credentials or no password at all. Successful exploitation provides the attacker with the privileges of the affected account, which can be used for further lateral movement or local privilege escalation. The issue is mitigated by enforcing strong password policies and ensuring all system accounts are properly secured during installation and maintenance.
Affected products
- Unix Unix All versions with default/null passwords
- Sun Solaris 2.5.1, 7.0, 8.0
- Sun SunOS 5.5.1, 5.7, 5.8
Timeline
- 1998-03-01: disclosed