PT-2022-21193 · Starwind · Starwind Stack+1

Published

2022-06-03

·

Updated

2022-11-16

·

CVE-2022-32268

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions StarWind SAN and NAS version 0.2 build 1914
Description A flaw was found in the REST API of StarWind Stack, allowing remote code execution. The REST command for changing the hostname does not check the new hostname parameter, which can be exploited by an attacker with non-root user access to inject arbitrary data into the command. This command is executed with root privileges, posing a significant risk.
Recommendations For StarWind SAN and NAS version 0.2 build 1914, consider restricting access to the REST API endpoint that allows changing the hostname until a patch is available. As a temporary workaround, limit the ability of non-root users to interact with this endpoint to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2022-32268

Affected Products

Starwind San/Nas
Starwind Stack