CVE-2016-1560 affects ExaGrid appliances running firmware older than 4.8 P26, stemming from the use of hardcoded default credentials for both the root shell and web interface support accounts. This critical vulnerability, with a CVSS score of 9.8, allows unauthenticated remote attackers to gain full administrative control over affected devices via SSH or HTTP. While not listed on the KEV catalog, public exploit modules, including a Metasploit module, are readily available, indicating a high potential for exploitation despite a lack of widespread community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.8CPE matchmatch criteria | cpe:2.3:o:exagrid:ex3000_firmware:4.8:*:*:*:*:*:*:* | ||
4.8CPE matchmatch criteria | cpe:2.3:o:exagrid:ex5000_firmware:4.8:*:*:*:*:*:*:* | ||
4.8CPE matchmatch criteria | cpe:2.3:o:exagrid:ex7000_firmware:4.8:*:*:*:*:*:*:* | ||
4.8CPE matchmatch criteria | cpe:2.3:o:exagrid:ex10000e_firmware:4.8:*:*:*:*:*:*:* | ||
4.8CPE matchmatch criteria | cpe:2.3:o:exagrid:ex13000e_firmware:4.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.