peter bassill · operator
$ cve CVE-2016-1560 JSON

CVE-2016-1560 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 72.3% (pctl 99)

Patch early

A public exploit exists.

Description

ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS72.29% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploityes
Published2017-04-21
Last modified2026-06-17

Affected (16)

VendorProduct
exagridex10000e
exagridex10000e firmware
exagridex13000e
exagridex13000e firmware
exagridex21000e
exagridex21000e firmware
exagridex3000
exagridex3000 firmware
exagridex32000e
exagridex32000e firmware
exagridex40000e
exagridex40000e firmware
exagridex5000
exagridex5000 firmware
exagridex7000
exagridex7000 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD