Synopsis
The remote web application is protected using default credentials.
Description
The remote host is running HP Discovery & Dependency Mapping Inventory (DDMI), which is used to automate discovery and inventory of network devices.
The remote installation of HP DDMI has at least one account configured using default credentials. Knowing these, an attacker can gain access to the affected application, possibly even as an administrator.
Solution
Change the password of any reported user.
Plugin Details
File Name: hp_ddmi_default_creds.nasl
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:hp:discovery%26dependency_mapping_inventory
Excluded KB Items: global_settings/supplied_logins_only