The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.
| Software | From | Fixed in |
|---|---|---|
| sun / sunos | 5.8 | 5.8.x |
| sun / solaris | 9.0 | 9.0.x |
| sun / solaris | 8.0 | 8.0.x |