CVE-2016-1560 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 72.3% (pctl 99)
Patch early
A public exploit exists.
Description
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 72.29% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-04-21 |
| Last modified | 2026-06-17 |
Affected (16)
| Vendor | Product |
|---|---|
| exagrid | ex10000e |
| exagrid | ex10000e firmware |
| exagrid | ex13000e |
| exagrid | ex13000e firmware |
| exagrid | ex21000e |
| exagrid | ex21000e firmware |
| exagrid | ex3000 |
| exagrid | ex3000 firmware |
| exagrid | ex32000e |
| exagrid | ex32000e firmware |
| exagrid | ex40000e |
| exagrid | ex40000e firmware |
| exagrid | ex5000 |
| exagrid | ex5000 firmware |
| exagrid | ex7000 |
| exagrid | ex7000 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ExaGrid - Known SSH Key and Default Password (Metasploit) | 2016-04-07 |
References
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials
→ the Explorer · watch your stack · NVD