CVE-2000-0384: Critical severity Intel Netstructure 7180 vulnerability

Published May 8, 2000
·
Updated

NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access.

Affected Software

2 affected components
Intel Netstructure 7180
Intel Netstructure 7110

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable or remove the undocumented accounts 'servnow', 'root', and 'wizard' on affected NetStructure 7110 and 7180 devices if they are not required, using the device management interface or CLI.

    Intel NetStructure 7110 / 7180 account_enabled (servnow, root, wizard) = disabled
  2. Compensating control

    Restrict network access to the management interfaces of affected NetStructure 7110 and 7180 devices (for example, via firewall rules, ACLs, or network segmentation) to trusted IPs only until the accounts are removed, disabled, or secured.

  3. Operational

    Change the passwords for the 'servnow', 'root', and 'wizard' accounts to strong, unique passwords if the accounts must remain. If passwords cannot be changed to non-guessable values, disable or remove the accounts.

Event History

May 8, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Jun 15, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0384?

CVE-2000-0384 is considered a high severity vulnerability due to the ability for attackers to gain root access remotely.

2

How do I fix CVE-2000-0384?

To fix CVE-2000-0384, it is recommended to disable the undocumented accounts or change their default passwords that could be guessed using the MAC address.

3

Which devices are affected by CVE-2000-0384?

CVE-2000-0384 affects Intel Netstructure 7110 and 7180 devices.

4

Can CVE-2000-0384 be exploited without physical access?

Yes, attackers can exploit CVE-2000-0384 remotely due to the easily guessable passwords.

5

What are the default usernames associated with CVE-2000-0384?

The default usernames associated with CVE-2000-0384 are servnow, root, and wizard.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203