Vulnerabilities > CVE-2014-3419 - Credentials Management vulnerability in Infoblox Netmri
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Infoblox NetMRI before 6.8.5 has a default password of admin for the "root" MySQL database account, which makes it easier for local users to obtain access via unspecified vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/127410/infoblox-passwd.txt |
id | PACKETSTORM:127410 |
last seen | 2016-12-05 |
published | 2014-07-09 |
reporter | Nate Kettlewell |
source | https://packetstormsecurity.com/files/127410/Infoblox-6.8.4.x-Weak-MySQL-Password.html |
title | Infoblox 6.8.4.x Weak MySQL Password |
References
- http://blog.depthsecurity.com/2014/07/os-command-injection-in-infoblox-netmri.html
- http://packetstormsecurity.com/files/127410/Infoblox-6.8.4.x-Weak-MySQL-Password.html
- http://www.securityfocus.com/archive/1/532710/100/0/threaded
- http://www.securityfocus.com/bid/68473
- http://www.securitytracker.com/id/1030542
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94450
- https://github.com/depthsecurity/NetMRI-2014-3418