First published: Wed Aug 29 2001(Updated: )
Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AXENT NetProwler | =3.5.1 | |
AXENT NetProwler | =3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0645 is considered a medium severity vulnerability due to the presence of default passwords allowing unauthorized remote access.
To fix CVE-2001-0645, change the default passwords for the management tier and MySQL ODBC connections immediately.
The risks associated with CVE-2001-0645 include unauthorized access to sensitive system configurations and possible data exposure.
CVE-2001-0645 affects AXENT NetProwler versions 3.5 and 3.5.1 specifically.
Yes, CVE-2001-0645 can be exploited remotely due to default passwords that allow access to the management tier.