CVE-2016-1560
Summary
| CVE | CVE-2016-1560 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-21 20:59:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-798 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Exagrid | Ex10000e | - | All | All | All |
| Operating System | Exagrid | Ex10000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex13000e | - | All | All | All |
| Operating System | Exagrid | Ex13000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex21000e | - | All | All | All |
| Operating System | Exagrid | Ex21000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex3000 | - | All | All | All |
| Operating System | Exagrid | Ex3000 Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex32000e | - | All | All | All |
| Operating System | Exagrid | Ex32000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex40000e | - | All | All | All |
| Operating System | Exagrid | Ex40000e Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex5000 | - | All | All | All |
| Operating System | Exagrid | Ex5000 Firmware | 4.8 | All | All | All |
| Hardware | Exagrid | Ex7000 | - | All | All | All |
| Operating System | Exagrid | Ex7000 Firmware | 4.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ExaGrid Known SSH Key and Default Password | af854a3a-2127-422b-91ae-364da2661108 | www.rapid7.com | Third Party Advisory |
| R7-2016-04: Exagrid Backdoor SSH Keys and Hardc... | Rapid7 Community and Blog | af854a3a-2127-422b-91ae-364da2661108 | community.rapid7.com | Exploit, Mitigation, Third Party Advisory |
| ExaGrid Known SSH Key / Default Password ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.