CVE-2016-1561

ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:exagrid:ex3000_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex3000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:exagrid:ex5000_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex5000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:exagrid:ex7000_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex7000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:exagrid:ex10000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex10000e:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:exagrid:ex13000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex13000e:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:exagrid:ex21000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex21000e:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:exagrid:ex32000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex32000e:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:exagrid:ex40000e_firmware:4.8:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:ex40000e:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:46

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html - Exploit, Third Party Advisory, VDB Entry
References () http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey - Third Party Advisory () http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey - Third Party Advisory
References () https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials - Exploit, Mitigation, Third Party Advisory () https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials - Exploit, Mitigation, Third Party Advisory

Information

Published : 2017-04-21 20:59

Updated : 2024-11-21 02:46


NVD link : CVE-2016-1561

Mitre link : CVE-2016-1561

CVE.ORG link : CVE-2016-1561


JSON object : View

Products Affected

exagrid

  • ex13000e_firmware
  • ex3000_firmware
  • ex13000e
  • ex21000e_firmware
  • ex40000e
  • ex5000_firmware
  • ex3000
  • ex5000
  • ex32000e
  • ex7000_firmware
  • ex21000e
  • ex32000e_firmware
  • ex7000
  • ex40000e_firmware
  • ex10000e_firmware
  • ex10000e
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor