PT-2022-16714 · Starwind · Starwind San/Nas

Published

2022-02-06

·

Updated

2022-09-01

·

CVE-2022-24551

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions StarWind SAN and NAS versions 0.2 build 1633 through 0.2 build 1684
Description A flaw was found in the password reset endpoint, which does not properly check the current username and old password. This allows an attacker to reset any local user password, including system or administrator user passwords, using any available user account.
Recommendations For StarWind SAN and NAS versions 0.2 build 1633 through 0.2 build 1684, update to version 0.2 build 1685 or later to resolve the issue. As a temporary workaround, consider restricting access to the password reset endpoint until the update can be applied.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-24551

Affected Products

Starwind San/Nas