Executive brief
A web-accessible resource is protected by a password that is easily guessed by unauthorized users. This allows an attacker to gain unauthorized access to restricted areas of a website, potentially leading to the exposure of sensitive data or unauthorized modifications. Organizations should ensure all web-based authentication uses strong, complex passwords that are not susceptible to simple guessing or dictionary attacks.
Technical details
The vulnerability involves the use of weak or default credentials for web-based authentication (WWW URL). Because the password is 'guessable,' it implies a lack of complexity or the use of common dictionary terms, making it susceptible to brute-force or manual guessing attacks. An unauthenticated remote attacker can exploit this to bypass access controls. Successful exploitation grants the attacker the privileges associated with the compromised account, which may include viewing private content, modifying data, or disrupting service availability. Mitigation requires enforcing strong password policies or implementing multi-factor authentication.
Timeline
- 1997-07-01: disclosed: Initial publication date in NVD.