PT-2016-3201 · Exagrid · Exagrid
Egypt
·
Publicado
2016-01-26
·
Atualizado
2017-04-27
·
CVE-2016-1560
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ExaGrid appliances with firmware before 4.8 P26
Description
The issue is related to the use of default credentials in ExaGrid backup devices' firmware. Exploitation of this issue may allow a remote attacker to gain root access to the device using the default password 'inflection' for the root account via SSH or HTTP protocols. This could potentially allow administrative access to the device.
Recommendations
For ExaGrid appliances with firmware before 4.8 P26, update the firmware to version 4.8 P26 or later to change the default password for the root shell account and remove support for the default support account in the web interface.
As a temporary workaround, consider changing the default password for the root account and disabling the support account in the web interface until a firmware update can be applied.
Exploit
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Exagrid