The manufacturer’s default passwords must be changed for all Hardware Management Console (HMC) Management software.
An XCCDF Rule
Description
<VulnDiscussion>The changing of passwords from the HMC default values, blocks malicious users with knowledge of these default passwords, from creating a denial of service or from reconfiguring the HMC topology leading to a compromise of sensitive data. The system administrator will ensure that the manufacturer’s default passwords are changed for all HMC management software.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-256875r1001086_rule
- Severity
- High
- References
- Updated
Remediation - Manual Procedure
The System Administrator must logon to the HMC and validate that all Default Passwords have been changed.
User ID Default Password
OPERATOR PASSWORD
ADVANCED PASSWORD
SYSPROG PASSWORD