PT-2022-16714 · Starwind · Starwind San/Nas
Published
2022-02-06
·
Updated
2022-09-01
·
CVE-2022-24551
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
StarWind SAN and NAS versions 0.2 build 1633 through 0.2 build 1684
Description
A flaw was found in the password reset endpoint, which does not properly check the current username and old password. This allows an attacker to reset any local user password, including system or administrator user passwords, using any available user account.
Recommendations
For StarWind SAN and NAS versions 0.2 build 1633 through 0.2 build 1684, update to version 0.2 build 1685 or later to resolve the issue. As a temporary workaround, consider restricting access to the password reset endpoint until the update can be applied.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Starwind San/Nas