Default Accounts and Passwords
Default accounts and passwords are the pre-set login credentials that vendors ship with hardware devices, software, and applications for initial setup and testing. Because these defaults are widely documented and often published in public databases, attackers frequently try them as one of the easiest ways to gain unauthorized access to a system. Many vendors recommend changing these credentials, and replacing them helps reduce the risk of compromise.
Default accounts and passwords are pre-configured, vendor-supplied credentials intended for initial testing, installation, and configuration operations. Because such credentials are commonly enumerated in publicly maintained repositories spanning many vendors and devices, they present a well-known attack surface: trying default accounts and passwords is among the simplest techniques for penetrating a system. Hardening practice calls for changing or disabling vendor-supplied defaults—including default account names, passwords, and other security parameters—on network devices, applications, and endpoints before or immediately upon deployment. In a PCI DSS context, management of vendor-supplied defaults is addressed by the standard's system configuration and hardening requirements; because requirement numbering and wording differ between PCI DSS versions, practitioners should confirm the applicable requirement against the current published standard rather than assuming a fixed reference. This term is distinct from broader authentication controls such as multi-factor authentication and password strength policies, which address related but separate risks.
Why it matters
Default accounts and passwords represent one of the most well-known and easily exploited weaknesses in any system. Because vendors ship devices, applications, and network equipment with pre-set credentials for initial setup, and because those credentials are widely documented in publicly maintained repositories, an attacker who knows the make and model of a target system can often look up the factory defaults with little effort. As one industry auditor's account notes, trying default accounts and passwords is among the easiest ways to attempt access to a computer system, which is precisely why hardening guidance consistently emphasizes changing or disabling them.
The scale of the exposure is illustrated by public repositories that catalog default credentials across hundreds of vendors and thousands of individual passwords spanning network devices, applications, and endpoints. Government advisories, including guidance published by CISA, have highlighted the risks associated with leaving default passwords in place, noting that these credentials are intended only for initial testing, installation, and configuration and that many vendors recommend changing them. When defaults remain unchanged after deployment, they leave a standing, well-documented entry point that requires no sophisticated technique to abuse.
Addressing vendor-supplied defaults is a foundational element of system configuration and hardening. Removing or changing them helps reduce the risk of unauthorized access, but it is not a complete authentication strategy on its own; it works alongside other controls such as strong password policies and multi-factor authentication. Practitioners should treat changing defaults as a baseline step rather than a comprehensive safeguard.
Who it's relevant to
Inside Default Accounts and Passwords
Common questions
Answers to the questions practitioners most commonly ask about Default Accounts and Passwords.