RULE(RULE ID:332808)

Rule General Information
Release Date: 2021-03-26
Rule Name: HP SiteScope integrationViewer Default Credentials Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: A default credential vulnerability has been reported in HP SiteScope. On a fresh installation of SiteScope, the administrator account is accessible without a password and there is a user account called integrationViewer with a default password. A remote attacker can exploit these default credentials to access the SiteScope web interface. Once authenticated, the attacker can exploit additional policy-bypass and directory-traversal vulnerabilities. Through specially crafted requests, they allow the attacker to perform administrative tasks when authenticated as a non-administrative user and to read contents of arbitrary files.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.