Nortek Default SSH Credentials

critical Nessus Plugin ID 175106

Synopsis

An account on the remote host uses a known default password.

Description

The remote device is a Nortek device that uses a set of known, default credentials. An attacker who is able to connect to the service can use these credentials to gain control of the device.

Solution

Log in to the remote host and change the default login credentials.

Plugin Details

Severity: Critical

ID: 175106

File Name: nortek_ssh_default_creds.nasl

Version: 1.0

Type: remote

Published: 5/4/2023

Updated: 5/4/2023

Supported Sensors: Nessus

Risk Information

CVSS Score Rationale: Default credential score.

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:niceforyou:linear_emerge_e3_access_control_firmware

Excluded KB Items: global_settings/supplied_logins_only