HTTP: Null Password Authentication

This signature detects an HTTP request with authentication where the password is null. This is generally insecure.

Extended Description

It has been reported that, by default, the RDS service uses a blank password for authentication. This could allow an unauthenticated user to access the vulnerable ColdFusion MX server.

Affected Products

Macromedia coldfusion_server

Short Name
HTTP:INFO:NULL-AUTH
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Authentication Null Password bid:8110
Release Date
10/20/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Macromedia

Found a potential security threat?