Does the FusionVM scan attempt username and password brute force?
It does perform some username and password guessing; however, FusionVM does not perform an all-out brute force attempt against accounts. Many devices come with default administrative account names, and there are quite a few standard username/password combinations the system checks for. For example: 3Com’s hubs/switches default logon of manager:manager: Windows Network administrator:administrator or adminstrator:blank: MS-SQL sa:blank. While it is checking for the basics and the defaults, FusionVM will not perform straight brute force attempts against logins, as there is too great a risk of causing a Denial of Service situation by locking out accounts.