MITRE Caldera is an open-source adversary-emulation and command-and-control framework. It is developed and maintained by MITRE as a platform for automated security testing. Red teams and penetration testers use it to emulate adversary behavior mapped to the MITRE ATT&CK knowledge base. It drives lightweight agents deployed on target hosts and runs abilities and full operations against them. Blue teams rely on it to validate and tune their detection and response capabilities. It is typically deployed as a self-hosted web application that operators reach through a browser-based console.
Caldera ships with a set of built-in operator accounts for its web console. When the server is started with its insecure default configuration, these accounts stay active with well-known static passwords. The scanner checks whether a reachable instance still accepts those default credentials. It targets the authentication flow that is shared by both the classic and the newer console. A successful login confirms that the deployment is left in an exposed state. This reflects a common misconfiguration where unique credentials are never set before the server is published.
The scanner first requests the login page to confirm that the target is a genuine Caldera instance. It then submits credentials to the /enter authentication endpoint using the username and password form parameters. Both the v4 classic console and the v5 Magma console expose this same endpoint. On a valid login the server issues an API_SESSION session cookie, which is used as the success signal. The default operator accounts red, blue, and admin are each attempted with the default password. The initial login-page fingerprint keeps the check scoped to Caldera and avoids false positives on unrelated applications.
Access through default credentials grants an attacker an authenticated session with full operator privileges on the console. From there the attacker can register agents, run abilities, and execute arbitrary commands on every connected host. Because Caldera is a command-and-control platform, this effectively hands the attacker a ready-made offensive infrastructure inside the environment. The result can be complete compromise of the managed hosts, lateral movement, and theft or destruction of sensitive data.
REFERENCES
- Replace the built-in red, blue, and admin accounts with unique operator accounts that use strong, unpredictable passwords.
- Never run the server with the insecure default configuration in any environment that is reachable by others.
- Restrict the console to trusted networks or place it behind a VPN or access proxy.
- Rotate account passwords and the server session secret on a regular schedule.
- Review the configured user list periodically and remove any account that is no longer needed.
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →