Vulnerabilities (CVE)

Filtered by vendor Qsan Subscribe
Filtered by product Storage Manager
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-32525 1 Qsan 1 Storage Manager 2021-09-20 9.0 HIGH 7.2 HIGH
The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.
CVE-2021-32524 1 Qsan 1 Storage Manager 2021-09-20 6.5 MEDIUM 7.2 HIGH
Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
CVE-2021-32526 1 Qsan 1 Storage Manager 2021-09-20 4.0 MEDIUM 6.5 MEDIUM
Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Suggest contacting with QSAN and refer to recommendations in QSAN Document.