Vulnerabilities > CVE-2014-5334 - 7PK - Security Features vulnerability in Freenas

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
freenas
CWE-254
critical
nessus

Summary

FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.

Common Weakness Enumeration (CWE)

Nessus

NASL familyCGI abuses
NASL idFREENAS_WEBGUI_BLANK_PASSWORD.NASL
descriptionThe version of FreeNAS installed on the remote host either has not yet set up a password or has recently reset the WebGUI password. This allows anyone to log into the WebGUI, set up an arbitrary password, and then use the system terminal feature of the WebGUI to execute arbitrary commands with administrative privileges.
last seen2020-06-01
modified2020-06-02
plugin id77746
published2014-09-18
reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/77746
titleFreeNAS WebGUI Blank Password