Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 943
  • Last Modified:

Cajun P550 Lucent Switch Manament console reset root password

I have recently started w/ a company and the password that was set on the Cajun P550 Management port(root user) is missing(no one remembers it). How do I go about reseting the swith to the default setting(like from the factory).
I need to setup more ports on the switch and configure the some VLAN port. I am unable to do so until I can logon.
0
jszarka
Asked:
jszarka
1 Solution
 
jszarkaAuthor Commented:
I answered it myself, I am posting for others to use.
Security alert, thank god for security holes
*******************************************************
Vulnerable systems:
 * Avaya Cajun P580 software version 5.2.14

Immune systems:
 * Avaya Cajun P580 software version 5.3.0

All previous software versions are assumed to be vulnerable. This problem is present in Cajun P550, P550R,P580,P880 and P882.

Details:
The vulnerable firmware installs the following strings into the switch configuration by default:

username "root" password encrypted-type1 "$tSfIcnbTP.pxRf7BrhGW31" access-type admin
username "diag" password encrypted-type1 "$PQO.vGxkvDHkEDCJ2YsoD1" access-type read-write
username "manuf" password encrypted-type1 "$seHFLP9b16m2v/534WCk90" access-type read-write

The only documented password is for the root user. This user can't change the diag and manuf accounts.

The un-documented passwords are:
user password
---- --------
diag danger
manuf xxyyzz

Both of these accounts give developer access to the switch (read-write access-type), which is more privileged than normal administrative access (admin access-type).

Recommendations:
As always it is good administrative practice to block access to administrative interfaces (telnet, web) at the firewall. Upgrading to software version 5.3.0 or later and disabling the accounts resolves this issue.

As a temporary workaround download the configuration file via TFTP, edit out these accounts, or change their password hashes, and upload it to the switch.

Vendor status:
AVAYA was informed on 2 Oct 2002. The vendor responded the same day, proved responsive and worked promptly on the problem. Jacek has agreed to release the information after the release of the official AVAYA advisory. The official Avaya advisory was out on 11 Oct 2002. The fixed software is available from the Avaya support site http://support.avaya.com/.
0
 
moduloCommented:
PAQed with points refunded (500)

modulo
Community Support Moderator
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

NEW Internet Security Report Now Available!

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out this quarters report on the threats that shook the industry in Q4 2017.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now