Finding Known Default Credentials

Many breaches start with a password that was never changed from the factory setting. Analog Informatics Corporation (AIC) kits find systems and devices on your network, match each one to published vendor default credentials, and flag the ones that still use a dangerous default so they can be changed.

An old generic key inspected under a precision magnifying lens beside a secure credential vault
Finding Known Default Credentials

This is built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits. In industry terms it is part of identity security posture management (ISPM).

Short Answers

What does the kit look for?

Vendor factory usernames and passwords that are published for operating systems, network devices, operational technology (OT) devices such as industrial controllers, and applications.

Where do the default credential lists come from?

From licensed public sources bundled with the product, including the DefaultCreds Cheat Sheet (MIT license), SecLists default and SCADA credentials (MIT), SCADAPASS (CC-BY-4.0), and a curated list from Cybersecurity and Infrastructure Security Agency (CISA) industrial control system advisories (a US Government work). Organizations can add their own lists.

How does it find the devices?

A built-in network scanner checks IPv4 and IPv6 ranges for live hosts, open ports, and vendor signatures. Each signature is matched to the entries in the catalog that apply to that platform.

Does it try a default password on every device?

No. A device is a candidate only when its signature matches a catalog entry. If the kit already holds a working, non-default credential for that system, the check is skipped.

What happens when a default is found?

The system is marked as using a dangerous default in the Systems List. The fix is to change it to a strong, platform-appropriate random password. Privileged Identity Management (PIM) can vault and rotate it from then on.

Is the scanner's cryptography validated?

The scanner uses the AWS-LC cryptographic module, validated under FIPS 140-3 (CMVP certificate 4759).

What Is Covered

Capability

  • IPv4 and IPv6 network scan with port profiles and custom port lists
  • Editable catalog of known default credentials
  • Bundled dictionaries from licensed public sources, with reload and fetch-latest
  • Customer-supplied dictionaries
  • Platform password patterns
  • Signature matching to catalog entries
  • Skip when a working non-default credential is already known
  • "Dangerous default" flag on the Systems List
  • Operational technology (OT) and network device checks
  • Vulnerability analysis of discovered systems

Scan only networks and systems you own or are authorized to assess.

Screenshots

The built-in scanner finds hosts and open management ports across IPv4 and IPv6 ranges.
The kit checks for dangerous vendor default passwords, including on operational technology devices.
Default credential dictionaries come from licensed public sources, with the license shown for each.

Related Controls

Framework Controls
NIST SP 800-53 IA-5, CM-6, CM-8, RA-5
NIST SP 800-171 3.4.1, 3.5.7, 3.11.2
CMMC CM.L2-3.4.1, IA.L2-3.5.7
IEC 62443 SR 1.5 (authenticator management)

An assessment organization, and in some cases the government, decides whether an organization meets a framework.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.