← All CVEs

CVE-2016-1560

critical · 9.8

ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.

9.8
CVSS
72.3%
EPSS (exploit prob.)
99th
EPSS percentile
2017-04-21
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-798

Affected products

VendorProductAffected versions
exagridex3000_firmware4.8
exagridex3000all versions
exagridex5000_firmware4.8
exagridex5000all versions
exagridex7000_firmware4.8
exagridex7000all versions
exagridex10000e_firmware4.8
exagridex10000eall versions
exagridex13000e_firmware4.8
exagridex13000eall versions
exagridex21000e_firmware4.8
exagridex21000eall versions
exagridex32000e_firmware4.8
exagridex32000eall versions
exagridex40000e_firmware4.8
exagridex40000eall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-1560