Vulnerabilities > Exagrid

DATE CVE VULNERABILITY TITLE RISK
2019-06-03 CVE-2019-12310 Path Traversal vulnerability in Exagrid Backup Appliance Firmware 48.1.1044.P50
ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability, which allows remote attackers to view and retrieve verbose logging information.
network
low complexity
exagrid CWE-22
critical
9.8
2017-04-21 CVE-2016-1561 Information Exposure vulnerability in Exagrid products
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.
network
low complexity
exagrid CWE-200
7.5
2017-04-21 CVE-2016-1560 Use of Hard-coded Credentials vulnerability in Exagrid products
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.
network
low complexity
exagrid CWE-798
critical
9.8