First published: Tue Feb 08 2005(Updated: )
The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.8 | |
Oracle Solaris SPARC | =9.0 | |
Oracle Solaris SPARC | =9.0 | |
Oracle Solaris SPARC | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0248 has a moderate severity rating due to the potential for unauthorized access to user accounts with blank passwords.
To fix CVE-2005-0248, ensure that all user accounts created with password aging have properly set passwords.
CVE-2005-0248 affects Solaris 8 and 9, specifically SunOS 5.8 and Solaris 9.0 for both x86 and SPARC architectures.
CVE-2005-0248 affects user accounts configured for password aging that were created with the Solaris Management Console.
Yes, CVE-2005-0248 can be exploited by remote attackers if they gain access to accounts with blank passwords.