PT-2022-21193 · Starwind · Starwind Stack+1
Published
2022-06-03
·
Updated
2022-11-16
·
CVE-2022-32268
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
StarWind SAN and NAS version 0.2 build 1914
Description
A flaw was found in the REST API of StarWind Stack, allowing remote code execution. The REST command for changing the hostname does not check the new hostname parameter, which can be exploited by an attacker with non-root user access to inject arbitrary data into the command. This command is executed with root privileges, posing a significant risk.
Recommendations
For StarWind SAN and NAS version 0.2 build 1914, consider restricting access to the REST API endpoint that allows changing the hostname until a patch is available. As a temporary workaround, limit the ability of non-root users to interact with this endpoint to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Starwind San/Nas
Starwind Stack