CVE-2016-1561
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.
Published:Apr 21, 2017
Last Modified:Apr 20, 2025
EPS:Apr 21, 2017
EPSS Score:0.84403
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Exagrid
Product
Ex10000e
Exagrid
Ex10000e
Vendor
Exagrid
Product
Ex10000e Firmware
Exagrid
Ex10000e Firmware
Vendor
Exagrid
Product
Ex13000e
Exagrid
Ex13000e
Vendor
Exagrid
Product
Ex13000e Firmware
Exagrid
Ex13000e Firmware
Vendor
Exagrid
Product
Ex21000e
Exagrid
Ex21000e
Vendor
Exagrid
Product
Ex21000e Firmware
Exagrid
Ex21000e Firmware
Vendor
Exagrid
Product
Ex3000
Exagrid
Ex3000
Vendor
Exagrid
Product
Ex3000 Firmware
Exagrid
Ex3000 Firmware
Vendor
Exagrid
Product
Ex32000e
Exagrid
Ex32000e
Vendor
Exagrid
Product
Ex32000e Firmware
Exagrid
Ex32000e Firmware
Vendor
Exagrid
Product
Ex40000e
Exagrid
Ex40000e
Vendor
Exagrid
Product
Ex40000e Firmware
Exagrid
Ex40000e Firmware
Vendor
Exagrid
Product
Ex5000
Exagrid
Ex5000
Vendor
Exagrid
Product
Ex5000 Firmware
Exagrid
Ex5000 Firmware
Vendor
Exagrid
Product
Ex7000
Exagrid
Ex7000
Vendor
Exagrid
Product
Ex7000 Firmware
Exagrid
Ex7000 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
