CVE-2016-1560
Estado: ModificadaCrítica (9.8)—
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 72%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (8)
CWE
- CWE-798
Referencias
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-1560",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-04-21T20:59:00.447",
"references": [
{
"url": "http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "cret@cert.org"
},
{
"url": "http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials",
"tags": [
"Exploit",
"Mitigation",
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials",
"tags": [
"Exploit",
"Mitigation",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session."
},
{
"lang": "es",
"value": "Los dispositivos ExaGrid con un firmware anterior a 4.8 P26 tienen una contraseña por defecto de (1) inflexión para la cuenta de root shell y (2) soporte para la cuenta de soporte en la interfaz web, lo que permite a atacantes remotos obtener acceso administrativo a través de una sesión SSH o HTTP."
}
],
"lastModified": "2026-06-17T00:42:10.057",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:exagrid:ex3000_firmware:4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB46D162-1FF2-40DE-B011-9D1B1236C1EC"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:exagrid:ex3000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B8F21614-C509-4356-92AB-D928FA4B3244"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:exagrid:ex5000_firmware:4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E374365-0452-4CC1-9C1C-A1A6A785D79E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:exagrid:ex5000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E7F69F5B-AEFF-4424-A2BE-D82D2196FB73"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:exagrid:ex7000_firmware:4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17F8EF90-AEAB-4D7F-BE60-E2FA72977B5E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:exagrid:ex7000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8854F063-DE4D-491B-A62A-315BF1570D14"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:exagrid:ex10000e_firmware:4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16B91929-3E28-4CBD-9839-A8636F80F94C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:exagrid:ex10000e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D21923E5-B1B7-4A5B-95FF-30606BF50F8D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:exagrid:ex13000e_firmware:4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AF64726-07AE-4C95-9ED7-FB0FDA7E65E9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:exagrid:ex13000e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E4ABEFC8-2E8E-4ED0-A9E2-ADC1C999EC4D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:exagrid:ex21000e_firmware:4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B96C708C-CD6B-4DB1-A694-A05E3FF71EBA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:exagrid:ex21000e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C33895D0-CFC1-45FB-887F-2FFA4974C16C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:exagrid:ex32000e_firmware:4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDCA6DD1-E977-426D-85DD-606D0D7C3518"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:exagrid:ex32000e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FBCECE29-B301-4028-8017-643A412495A6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:exagrid:ex40000e_firmware:4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D4F932E-550F-4D6F-A948-9B037C7F301A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:exagrid:ex40000e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "09BDFB2D-173B-4B47-9422-7E5FF37B3D04"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cret@cert.org"
}