First published: Thu Mar 18 2004(Updated: )
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
APC AP9606 | =3.0.1 | |
APC AP9606 | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0311 has a critical severity due to the use of a default password allowing remote unauthorized access.
To fix CVE-2004-0311, change the default password from TENmanUFactOryPOWER to a strong, unique password.
CVE-2004-0311 affects APC Web/SNMP Management SmartSlot Card versions 3.0 through 3.0.3 and 3.21.
You can detect CVE-2004-0311 by checking if your APC device still uses the default password for access.
CVE-2004-0311 can be exploited by remote attackers to gain unauthorized access to the device's management interface.