CVE-2016-1560
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Exagrid Ex3000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Exagrid Ex5000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Exagrid Ex7000 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Exagrid Ex10000e | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Exagrid Ex13000e | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Exagrid Ex21000e | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Exagrid Ex32000e | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.8 |
| Running on/with | Platform Versions |
|---|---|
Exagrid Ex40000e | All versions |
References (6)
Source: cret@cert.org
ExploitThird Party AdvisoryVDB Entry
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Timeline
No history available yet.