PT-2016-3201 · Exagrid · Exagrid

Egypt

·

Published

2016-01-26

·

Updated

2017-04-27

·

CVE-2016-1560

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ExaGrid appliances with firmware before 4.8 P26
Description The issue is related to the use of default credentials in ExaGrid backup devices' firmware. Exploitation of this issue may allow a remote attacker to gain root access to the device using the default password 'inflection' for the root account via SSH or HTTP protocols. This could potentially allow administrative access to the device.
Recommendations For ExaGrid appliances with firmware before 4.8 P26, update the firmware to version 4.8 P26 or later to change the default password for the root shell account and remove support for the default support account in the web interface. As a temporary workaround, consider changing the default password for the root account and disabling the support account in the web interface until a firmware update can be applied.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02481
CVE-2016-1560

Affected Products

Exagrid