PT-2016-3201 · Exagrid · Exagrid

Egypt

·

Publicado

2016-01-26

·

Atualizado

2017-04-27

·

CVE-2016-1560

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ExaGrid appliances with firmware before 4.8 P26
Description The issue is related to the use of default credentials in ExaGrid backup devices' firmware. Exploitation of this issue may allow a remote attacker to gain root access to the device using the default password 'inflection' for the root account via SSH or HTTP protocols. This could potentially allow administrative access to the device.
Recommendations For ExaGrid appliances with firmware before 4.8 P26, update the firmware to version 4.8 P26 or later to change the default password for the root shell account and remove support for the default support account in the web interface. As a temporary workaround, consider changing the default password for the root account and disabling the support account in the web interface until a firmware update can be applied.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02481
CVE-2016-1560

Produtos afetados

Exagrid