Stonefly

Storage Concentrator

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.16%
  • Veröffentlicht 30.06.2026 23:17:32
  • Zuletzt bearbeitet 01.07.2026 18:17:31

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can s...

  • EPSS 3.15%
  • Veröffentlicht 30.06.2026 23:17:32
  • Zuletzt bearbeitet 01.07.2026 18:17:31

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is proc...

  • EPSS 0.45%
  • Veröffentlicht 30.06.2026 23:17:28
  • Zuletzt bearbeitet 01.07.2026 18:17:31

Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthent...

  • EPSS 0.14%
  • Veröffentlicht 30.06.2026 23:17:27
  • Zuletzt bearbeitet 01.07.2026 18:17:31

Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credent...

  • EPSS 0.26%
  • Veröffentlicht 30.06.2026 22:27:37
  • Zuletzt bearbeitet 01.07.2026 18:17:31

Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary scri...

  • EPSS 0.73%
  • Veröffentlicht 12.07.2024 23:15:10
  • Zuletzt bearbeitet 14.03.2025 15:15:40

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information.

  • EPSS 1.32%
  • Veröffentlicht 12.07.2024 23:15:09
  • Zuletzt bearbeitet 15.04.2026 00:35:42

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.