CVE-2016-1560
Summary
| CVE | CVE-2016-1560 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-21 20:59:00 UTC |
| Updated | 2017-04-27 14:49:00 UTC |
| Description | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Exagrid | Ex10000e | - | All | All | All |
| Hardware | Exagrid | Ex10000e | - | All | All | All |
| Operating System | Exagrid | Ex10000e Firmware | 4.8 | All | All | All |
| Operating System | Exagrid | Ex10000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex13000e | - | All | All | All |
| Hardware | Exagrid | Ex13000e | - | All | All | All |
| Operating System | Exagrid | Ex13000e Firmware | 4.8 | All | All | All |
| Operating System | Exagrid | Ex13000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex21000e | - | All | All | All |
| Hardware | Exagrid | Ex21000e | - | All | All | All |
| Operating System | Exagrid | Ex21000e Firmware | 4.8 | All | All | All |
| Operating System | Exagrid | Ex21000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex3000 | - | All | All | All |
| Hardware | Exagrid | Ex3000 | - | All | All | All |
| Operating System | Exagrid | Ex3000 Firmware | 4.8 | All | All | All |
| Operating System | Exagrid | Ex3000 Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex32000e | - | All | All | All |
| Hardware | Exagrid | Ex32000e | - | All | All | All |
| Operating System | Exagrid | Ex32000e Firmware | 4.8 | All | All | All |
| Operating System | Exagrid | Ex32000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex40000e | - | All | All | All |
| Hardware | Exagrid | Ex40000e | - | All | All | All |
| Operating System | Exagrid | Ex40000e Firmware | 4.8 | All | All | All |
| Operating System | Exagrid | Ex40000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex5000 | - | All | All | All |
| Hardware | Exagrid | Ex5000 | - | All | All | All |
| Operating System | Exagrid | Ex5000 Firmware | 4.8 | All | All | All |
| Operating System | Exagrid | Ex5000 Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex7000 | - | All | All | All |
| Hardware | Exagrid | Ex7000 | - | All | All | All |
| Operating System | Exagrid | Ex7000 Firmware | 4.8 | All | All | All |
| Operating System | Exagrid | Ex7000 Firmware | 4.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| R7-2016-04: Exagrid Backdoor SSH Keys and Hardc... | Rapid7 Community and Blog | MISC | community.rapid7.com | Exploit, Mitigation, Third Party Advisory |
| ExaGrid Known SSH Key / Default Password ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| ExaGrid Known SSH Key and Default Password | MISC | www.rapid7.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.