Vulnerability record · CVE-2016-1560 · published 21 April 2017
CVE-2016-1560: ExaGrid appliances default root and support credentials allow admin access
Exagrid · Ex3000 Firmware
ExaGrid appliances running firmware before 4.8 P26 ship with a default password of 'inflection' for the root shell account and a default password for the support account in the web interface. Because these credentials are static and publicly documented, anyone who can reach the appliance can log in with full administrative rights. This is a hard-coded/default credential flaw (CWE-798) affecting the entire ExaGrid firmware line.
Description
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, publicly available exploit tooling, and very high EPSS probability make this trivially exploitable for full administrative compromise.
What it is
ExaGrid appliances running firmware before 4.8 P26 ship with a default password of 'inflection' for the root shell account and a default password for the support account in the web interface. Because these credentials are static and publicly documented, anyone who can reach the appliance can log in with full administrative rights. This is a hard-coded/default credential flaw (CWE-798) affecting the entire ExaGrid firmware line.
Impact
An attacker gains administrative access to the appliance via SSH or the web interface, exposing backup data, configuration and the underlying system. With root shell access, the appliance can be fully controlled, data can be read, altered or destroyed, and it can be used as a pivot into the backup network.
Attack surface
Reachable over the network through SSH or HTTP sessions to the appliance; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. Any host that can route to the appliance's management interfaces can attempt the default credentials.
Exploitation
Not listed in CISA KEV, but EPSS is 0.72289 (99.4th percentile) and multiple references are tagged Exploit, including a Rapid7 Metasploit module and a Packet Storm advisory, so public exploitation tooling exists.
What to do
- Upgrade ExaGrid firmware to 4.8 P26 or later, which removes the default credentials.
- Immediately change the root and support account passwords on any appliance that cannot be patched.
- Restrict SSH and web management access to trusted administrative networks using firewall rules or ACLs.
- Disable or rename the support account if it is not required, and audit for any other default accounts.
- Monitor authentication logs for successful logins using the known default credentials.
Detection
- Search SSH and web authentication logs for successful logins to root or support accounts from unexpected source IPs.
- Alert on authentication attempts using the known default password 'inflection' or the support account default.
- Inventory ExaGrid appliances and verify firmware version is 4.8 P26 or later.
- Monitor for new SSH sessions or web admin sessions originating outside the management network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey | Third Party Advisory |
| https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-creden | ExploitMitigationThird Party Advisory |
| http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey | Third Party Advisory |
| https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-creden | ExploitMitigationThird Party Advisory |
Track CVE-2016-1560 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-1560), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.