Scalar i500, i2000, and i6000 Security - Service Account

If you're using a Quantum, Dell, or ADIC Scalar product you should check to see if the password of the GUI's 'service' account is static. If it is then there is a pretty trivial way to get into the system using the vendor's maintenance account. The one system I have access to, an i2000, has a login of service:10101100. 

Scalar i500, i2000, and i6000 Security - Service Port

If you're using a Quantum, Dell, or ADIC Scalar product you need to make sure the 'service port' isn't remotely accessible. If it is then there is a pretty trivial way to get into the system as 'root'. The port is explicitly listed in the manual as not for "normal" use. 

tl;dr If you aren't plugging in stuff you shouldn't (per manual) then the risk isn't that bad. 

Subscribe to Security