CVE-2016-1561

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
21/04/2017
Last modified:
20/04/2025

Description

ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:exagrid:ex3000_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex3000:-:*:*:*:*:*:*:*
cpe:2.3:o:exagrid:ex5000_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex5000:-:*:*:*:*:*:*:*
cpe:2.3:o:exagrid:ex7000_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex7000:-:*:*:*:*:*:*:*
cpe:2.3:o:exagrid:ex10000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex10000e:-:*:*:*:*:*:*:*
cpe:2.3:o:exagrid:ex13000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex13000e:-:*:*:*:*:*:*:*
cpe:2.3:o:exagrid:ex21000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex21000e:-:*:*:*:*:*:*:*
cpe:2.3:o:exagrid:ex32000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex32000e:-:*:*:*:*:*:*:*
cpe:2.3:o:exagrid:ex40000e_firmware:4.8:*:*:*:*:*:*:*