CVE-2016-1560
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 72%
from disclosure to weapon0 days
Published on NVDApr 21
1st PoCApr 7
metasploitApr 7
exploitation probability
72%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/41680cve_referencepacketstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.