J-Security Center

Title: Arkeia Server Blank Default Root Password Vulnerability

Severity: HIGH

Description:

Arkeia Server is an enterprise-based backup software solution distributed and maintained by Knox Software.

A problem with Arkeia has been discovered that makes it possible to gain access to the Arkeia server with elevated privileges in the Arkeia environment.

During a default install of the Arkeia software, the Arkeia root password is set to a value of null. Under normal conditions, once the software is fully installed, the administrator sets the root password for the Arkeia software.

However, if the software package is installed on an insecure network, it is possible for a remote user to gain access to the system before the password is set by the administator. This can be accomplished by remotely connecting to the Arkeia server using an Arkeia client, and logging in as root.

Affected Products:

  • Knox Software Arkeia 4.0.0
  • Knox Software Arkeia 4.1.0
  • Knox Software Arkeia 4.2.0
  • Knox Software Arkeia 5.2.0
  • Knox Software Arkeia 5.3.0
  • Knox Software Arkeia Server 4.2.8 -2
  • S.u.S.E. Linux 6.2.0

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.