← All CVEs

CVE-2016-1561

high · 7.5

ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.

7.5
CVSS
74.3%
EPSS (exploit prob.)
99th
EPSS percentile
2017-04-21
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
exagridex3000_firmware4.8
exagridex3000all versions
exagridex5000_firmware4.8
exagridex5000all versions
exagridex7000_firmware4.8
exagridex7000all versions
exagridex10000e_firmware4.8
exagridex10000eall versions
exagridex13000e_firmware4.8
exagridex13000eall versions
exagridex21000e_firmware4.8
exagridex21000eall versions
exagridex32000e_firmware4.8
exagridex32000eall versions
exagridex40000e_firmware4.8
exagridex40000eall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-1561