CVE-2025-29556
7.3ExaGrid · EX10
ExaGrid EX10 appliances in versions 6.3 through 7.0.1.P08 contain an access control flaw allowing administrative users to bypass security restrictions during account creation.
Executive summary
A critical access control vulnerability in ExaGrid EX10 appliances enables administrative users to escalate privileges to the Security Officer role, bypassing mandatory approval workflows.
Vulnerability
This vulnerability involves incorrect access control, specifically a flaw in the API request handling process. An attacker holding Admin privileges can manipulate API requests to assign the Security Officer role to new accounts without the required authorization, effectively bypassing established security governance.
Business impact
The ability to arbitrarily elevate privileges to the Security Officer level poses a severe risk to data integrity and system confidentiality. Because the Security Officer role is designed to oversee and restrict administrative actions, unauthorized access to this role could allow an actor to disable security logs, alter backup configurations, or exfiltrate sensitive data. With a CVSS score of 7.3, this flaw represents a High severity risk that could lead to full compromise of the backup infrastructure.
Remediation
Immediate Action: Organizations should verify their current firmware version and coordinate with ExaGrid support to apply the necessary security patches or configuration changes to address this API vulnerability.
Proactive Monitoring: Security teams should audit user account creation logs and monitor for unauthorized changes to the Security Officer group membership, paying close attention to API requests originating from administrative accounts.
Compensating Controls: Restrict access to the management API to known, trusted management workstations and implement strict network segmentation to limit the attack surface of the ExaGrid management interface.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as referenced in the GitHub repository provided by the vulnerability researchers.
Analyst recommendation
Given the potential for privilege escalation and the existence of a public proof-of-concept, this vulnerability must be addressed with high priority. Administrators should immediately audit existing Security Officer accounts for unauthorized additions and apply vendor-supplied patches to close the API manipulation vector. Failure to remediate this issue may result in an attacker gaining persistent, unauthorized control over critical backup security functions.