Exagrid develops backup and data-protection appliances serving mid-market and enterprise environments, with a vulnerability profile centered on its deduplication storage systems and their firmware. The durable signal reflects deployment-sensitive weakness classes including exposure of sensitive information, path-traversal conditions, and use of hard-coded credentials, which are characteristic concerns in remotely managed backup infrastructure. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exagrid over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1560CRITICAL ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, w | Apr 21, 2017 | 9.8 | 85 | NO | YES |
CVE-2016-1561HIGH ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging | Apr 21, 2017 | 7.5 | 82 | NO | YES |
CVE-2019-12310CRITICAL ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability, which allows remote attackers to view and retrieve verbose | Jun 3, 2019 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exagrid.
Media articles that mention a CVE ID that affects a product developed by Exagrid — matched by CVE ID, not by vendor name.