The Riverbed NetProfiler must change the default admin credentials so they do not use the default manufacturer passwords when deployed.
An XCCDF Rule
Description
<VulnDiscussion>Network devices not protected with strong password schemes provide the opportunity for anyone to crack the password and gain access to the device, which can result in loss of availability, confidentiality, or integrity of network traffic. Many default vendor passwords are well known or easily guessed; therefore, not removing them prior to deploying the network device into production provides an opportunity for a malicious user to gain unauthorized access to the device. By default, NetProfiler provides a single user account and password: The user name is admin with a weak default password. This user account is assigned the built-in role of Administrator, which provides the admin user account with unrestricted access to all NetProfiler features and data. At a minimum, change the default password to something less obvious and more complex. The default password is provided solely to enable logging in to the system and changing the configuration.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-256076r882736_rule
- Severity
- High
- References
- Updated
Remediation - Manual Procedure
Upon initial setup, log in to the NetProfiler web user interface using the "admin" user account and password.
Wait until the configuration wizard starts and provide the required information at the prompts. Follow the wizard and change the default password when prompted.
Change default system shell account passwords as required. The appliance is shipped with shell access enabled: