PT-2022-16715 · Starwind · Starwind Stack+1
Published
2022-02-06
·
Updated
2023-08-08
·
CVE-2022-24552
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
StarWind SAN and NAS version 0.2 build 1633
Description
A flaw was found in the REST API in StarWind Stack, where the REST command that manipulates a virtual disk does not check input parameters. Some of these parameters are directly executed as part of a bash script, allowing an attacker with non-root user access to inject arbitrary data into the command, which will be executed with root privileges.
Recommendations
For StarWind SAN and NAS version 0.2 build 1633, consider restricting access to the REST API until a patch is available. As a temporary workaround, avoid using the REST command that manipulates virtual disks to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Starwind San/Nas
Starwind Stack