October 22, 2016

TheHSecurity: Back door in HP network storage solution

HP’s P2000 G3 MSA Storage Area Network (SAN) product contains an hidden and undocumented account with more privileges than the normal customisable account (manage:!manage). Apparently included for support purposes, the account (admin:!admin) is not visible in the user manager and can’t be deleted or modified. It allows unauthorised users to access these systems and the data stored there.

Read the full story here.