PT-2025-17891 · Quantum · Activescale Cold Storage+3

Justine Osborne

·

Published

2025-04-25

·

Updated

2025-07-01

·

CVE-2025-46616

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions StorNext RYO versions prior to 7.2.4 StorNext Xcellis Workflow Director versions prior to 7.2.4 ActiveScale Cold Storage versions prior to 7.2.4 Quantum StorNext Web GUI API versions prior to 7.2.4
Description The issue allows potential Arbitrary Remote Code Execution (RCE) via upload of a file.
Recommendations For StorNext RYO versions prior to 7.2.4, update to version 7.2.4 or later. For StorNext Xcellis Workflow Director versions prior to 7.2.4, update to version 7.2.4 or later. For ActiveScale Cold Storage versions prior to 7.2.4, update to version 7.2.4 or later. For Quantum StorNext Web GUI API versions prior to 7.2.4, update to version 7.2.4 or later. As a temporary workaround, consider restricting file uploads to minimize the risk of exploitation.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-46616

Affected Products

Activescale Cold Storage
Quantum Stornext Web Gui Api
Stornext Ryo
Stornext Xcellis Workflow Director