?
Solved

Cajun P550 Lucent Switch Manament console reset root password

Posted on 2004-09-08
3
Medium Priority
?
931 Views
Last Modified: 2008-01-09
I have recently started w/ a company and the password that was set on the Cajun P550 Management port(root user) is missing(no one remembers it). How do I go about reseting the swith to the default setting(like from the factory).
I need to setup more ports on the switch and configure the some VLAN port. I am unable to do so until I can logon.
0
Comment
Question by:jszarka
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 

Author Comment

by:jszarka
ID: 12013007
I answered it myself, I am posting for others to use.
Security alert, thank god for security holes
*******************************************************
Vulnerable systems:
 * Avaya Cajun P580 software version 5.2.14

Immune systems:
 * Avaya Cajun P580 software version 5.3.0

All previous software versions are assumed to be vulnerable. This problem is present in Cajun P550, P550R,P580,P880 and P882.

Details:
The vulnerable firmware installs the following strings into the switch configuration by default:

username "root" password encrypted-type1 "$tSfIcnbTP.pxRf7BrhGW31" access-type admin
username "diag" password encrypted-type1 "$PQO.vGxkvDHkEDCJ2YsoD1" access-type read-write
username "manuf" password encrypted-type1 "$seHFLP9b16m2v/534WCk90" access-type read-write

The only documented password is for the root user. This user can't change the diag and manuf accounts.

The un-documented passwords are:
user password
---- --------
diag danger
manuf xxyyzz

Both of these accounts give developer access to the switch (read-write access-type), which is more privileged than normal administrative access (admin access-type).

Recommendations:
As always it is good administrative practice to block access to administrative interfaces (telnet, web) at the firewall. Upgrading to software version 5.3.0 or later and disabling the accounts resolves this issue.

As a temporary workaround download the configuration file via TFTP, edit out these accounts, or change their password hashes, and upload it to the switch.

Vendor status:
AVAYA was informed on 2 Oct 2002. The vendor responded the same day, proved responsive and worked promptly on the problem. Jacek has agreed to release the information after the release of the official AVAYA advisory. The official Avaya advisory was out on 11 Oct 2002. The fixed software is available from the Avaya support site http://support.avaya.com/.
0
 

Accepted Solution

by:
modulo earned 0 total points
ID: 12761915
PAQed with points refunded (500)

modulo
Community Support Moderator
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…
Suggested Courses
Course of the Month13 days, 8 hours left to enroll

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question