Vulnerability Description
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Exagrid | Ex3000 Firmware | 4.8 |
| Exagrid | Ex3000 | - |
| Exagrid | Ex5000 Firmware | 4.8 |
| Exagrid | Ex5000 | - |
| Exagrid | Ex7000 Firmware | 4.8 |
| Exagrid | Ex7000 | - |
| Exagrid | Ex10000E Firmware | 4.8 |
| Exagrid | Ex10000E | - |
| Exagrid | Ex13000E Firmware | 4.8 |
| Exagrid | Ex13000E | - |
| Exagrid | Ex21000E Firmware | 4.8 |
| Exagrid | Ex21000E | - |
| Exagrid | Ex32000E Firmware | 4.8 |
| Exagrid | Ex32000E | - |
| Exagrid | Ex40000E Firmware | 4.8 |
| Exagrid | Ex40000E | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-PasswoExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkeyThird Party Advisory
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagriExploitMitigationThird Party Advisory
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-PasswoExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkeyThird Party Advisory
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagriExploitMitigationThird Party Advisory
FAQ
What is CVE-2016-1561?
CVE-2016-1561 is a vulnerability with a CVSS score of 7.5 (HIGH). ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a priv...
How severe is CVE-2016-1561?
CVE-2016-1561 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1561?
Check the references section above for vendor advisories and patch information. Affected products include: Exagrid Ex3000 Firmware, Exagrid Ex3000, Exagrid Ex5000 Firmware, Exagrid Ex5000, Exagrid Ex7000 Firmware.