This writeup details a hardcoded root password and SSH private key vulnerability in Quantum DXi V1000 2.2.1 and below, allowing unauthorized root access via SSH. The analysis includes the exposed hash and private key, along with vendor communication and patch details.
Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:Quantum DXi V1000 2.2.1 and below
No auth needed
Prerequisites:Network access to the target system · SSH service exposed