Vulnerability Description
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Exagrid | Ex3000 Firmware | 4.8 |
| Exagrid | Ex3000 | - |
| Exagrid | Ex5000 Firmware | 4.8 |
| Exagrid | Ex5000 | - |
| Exagrid | Ex7000 Firmware | 4.8 |
| Exagrid | Ex7000 | - |
| Exagrid | Ex10000E Firmware | 4.8 |
| Exagrid | Ex10000E | - |
| Exagrid | Ex13000E Firmware | 4.8 |
| Exagrid | Ex13000E | - |
| Exagrid | Ex21000E Firmware | 4.8 |
| Exagrid | Ex21000E | - |
| Exagrid | Ex32000E Firmware | 4.8 |
| Exagrid | Ex32000E | - |
| Exagrid | Ex40000E Firmware | 4.8 |
| Exagrid | Ex40000E | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-PasswoExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkeyThird Party Advisory
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagriExploitMitigationThird Party Advisory
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-PasswoExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkeyThird Party Advisory
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagriExploitMitigationThird Party Advisory
FAQ
What is CVE-2016-1560?
CVE-2016-1560 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote a...
How severe is CVE-2016-1560?
CVE-2016-1560 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-1560?
Check the references section above for vendor advisories and patch information. Affected products include: Exagrid Ex3000 Firmware, Exagrid Ex3000, Exagrid Ex5000 Firmware, Exagrid Ex5000, Exagrid Ex7000 Firmware.