First published: Tue Sep 21 2004(Updated: )
Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec ON Command CCM | =5.2 | |
Symantec ON Command CCM | =5.3 | |
Symantec On Icommand | =3.0 | |
Symantec ON Command CCM | =5.4 | |
Symantec ON Command CCM | =5.1 | |
Symantec ON Command CCM | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1694 is considered a high severity vulnerability due to the potential for unauthorized remote access.
To fix CVE-2004-1694, change all default usernames and passwords to strong, unique credentials.
CVE-2004-1694 affects Symantec ON Command CCM versions 5.0 to 5.4 and iCommand version 3.0.
Yes, CVE-2004-1694 can be exploited remotely by attackers leveraging default credentials.
There is no specific patch for CVE-2004-1694; however, changing default credentials is a necessary mitigation.