20 lines
No EOL
627 B
Text
20 lines
No EOL
627 B
Text
Finding 4: Undocumented Default Accounts
|
|
CVE: CVE-2010-4233
|
|
|
|
The CMNC-200 IP Camera has undocumented default
|
|
accounts on its Linux operating system. These accounts can
|
|
be used to login via the cameras telnet interface, which
|
|
cannot be normally disabled. The usernames and passwords are
|
|
listed below.
|
|
|
|
User: root Password: m
|
|
User: mg3500 Password: merlin
|
|
|
|
Vendor Response:
|
|
No response received.
|
|
|
|
Remediation Steps:
|
|
No patch currently exists for this issue. To limit exposure,
|
|
network access to these devices should be limited to authorized
|
|
personnel through the use of Access Control Lists and proper
|
|
network segmentation. |