EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain potentially sensitive information via a login session.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0529
Reference (s):
- BUGTRAQ:20150401 ESA-2015-056: EMC PowerPath Virtual Appliance Undocumented User Accounts Vulnerability
- URL: http://seclists.org/bugtraq/2015/Apr/1
- http://packetstormsecurity.com/files/131250/EMC-PowerPath-Virtual-Appliance-Undocumented-User-Accounts.html