PoC Index

CVE-2016-1560

HIGH 10.0EPSS 72.3%

ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
72.29% chance of exploitation in the next 30 days, 99th percentile
Published
2017-04-21
Updated
2024-08-05

Proof-of-concept exploits (2)

Metasploit modules (1)

ExploitDB entries (1)

References

Related