Orphaned Account Checker

13. Vendor default or built-in account enabled

A built-in or vendor default account is known to anyone who has read the product's manual; one left enabled is the first thing tried.

The rule it applies

The account is a built-in or vendor default account (from the type column, or a whole account name such as admin, root, sa or guest) and does not read as disabled.

A question for the account owner

Is this default account used, and if so has its default password been changed?

Clauses

3 across the regimes you tick
RegimeClauseRead on
PCI DSSPCI DSS 2.2.2 Vendor default accounts managedevery account type
ISO/IEC 27001ISO/IEC 27001 A.5.17 Authentication informationevery account type
NIST SP 800-53NIST SP 800-53 IA-5 Authenticator Managementevery account type

The first clause, set out

PCI DSS 2.2.2Vendor default accounts managed

Vendor default accounts must be handled as follows: (a) where a vendor default account will be used, its default password is changed in line with Requirement 8.3.6; and (b) where it will stay unused, the account is disabled or deleted. Applicability: every vendor default account and password is covered, for example those of operating systems, security software, application and system accounts, POS terminals, payment applications and SNMP defaults; it also applies to components not installed in the entity's environment, such as CDE software and applications consumed through a cloud subscription. Objective under the customized approach: default passwords cannot be used to access system components.

What an auditor asks to see: Inventory of vendor default accounts per system type with disposition (used and re-passworded, or removed/disabled); Configuration files or directory exports showing unused default accounts disabled or deleted; Evidence that retained default accounts use passwords meeting Requirement 8.3.6; Observation record of failed log-on attempts using known default credentials; SNMP configuration showing default community strings changed
Where account lists usually fall short: Default credentials remain on POS terminals, network appliances or out-of-band management interfaces; SaaS or cloud subscription admin accounts retain vendor-provided initial passwords; Default accounts disabled but the default password left unchanged, allowing re-enablement
Source: PCI DSS v4.0

See it on the specimenAll fourteen findings