- EPSS 3.16%
- Veröffentlicht 30.06.2026 23:17:32
- Zuletzt bearbeitet 01.07.2026 18:17:31
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can s...
- EPSS 3.15%
- Veröffentlicht 30.06.2026 23:17:32
- Zuletzt bearbeitet 01.07.2026 18:17:31
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is proc...
CVE-2026-55721
- EPSS 0.45%
- Veröffentlicht 30.06.2026 23:17:28
- Zuletzt bearbeitet 01.07.2026 18:17:31
Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthent...
CVE-2026-50110
- EPSS 0.14%
- Veröffentlicht 30.06.2026 23:17:27
- Zuletzt bearbeitet 01.07.2026 18:17:31
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credent...
CVE-2026-50040
- EPSS 0.26%
- Veröffentlicht 30.06.2026 22:27:37
- Zuletzt bearbeitet 01.07.2026 18:17:31
Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary scri...
CVE-2024-31947
- EPSS 0.73%
- Veröffentlicht 12.07.2024 23:15:10
- Zuletzt bearbeitet 14.03.2025 15:15:40
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information.
CVE-2024-30213
- EPSS 1.32%
- Veröffentlicht 12.07.2024 23:15:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.