PT-2021-19746 · Qsan · Qsan Storage Manager

Published

2021-07-07

·

Updated

2021-09-21

·

CVE-2021-32520

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: QSAN Storage Manager (affected versions not specified)
Description: The issue involves the use of a hard-coded cryptographic key in QSAN Storage Manager, allowing attackers to obtain users' credentials and related permissions.
Recommendations: Contact QSAN and refer to the recommendations in the QSAN Document for guidance on resolving the issue. As a temporary workaround, consider restricting access to sensitive areas of QSAN Storage Manager to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32520

Affected Products

Qsan Storage Manager