Avaya P330 Stackable Switch Default Password

critical Nessus Plugin ID 17638

Synopsis

The remote switch can be accessed with default root credentials.

Description

The remote host appears to be an Avaya P330 Stackable Switch with its default password set.

An attacker could use this default password to gain remote access to the affected switch. This password could also be potentially used to gain other sensitive information about the remote network from the switch.

Solution

Telnet to this switch and change the default password.

See Also

http://www.phenoelit-us.org/dpl/dpl.html

Plugin Details

Severity: Critical

ID: 17638

File Name: avaya_switches.nasl

Version: Revision: 1.11

Type: remote

Family: Misc.

Published: 3/28/2005

Updated: 8/15/2012

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Exploitable With

Metasploit (SNMP Community Scanner)

Reference Information

CVE: CVE-1999-0508