Stonefly
Stonefly Storage Concentrator: vulnerabilidades y CVE
Stonefly Storage Concentrator tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses5
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-56415 | Crítica (10) | 4.4% | — | 30 jun 2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a… |
| CVE-2026-56413 | Crítica (10) | 4.2% | — | 30 jun 2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An… |
| CVE-2026-55721 | Crítica (9.2) | 0.55% | — | 30 jun 2026 | Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate… |
| CVE-2026-50110 | Crítica (9.3) | 0.18% | — | 30 jun 2026 | Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to… |
| CVE-2026-50040 | Media (5.1) | 0.33% | — | 30 jun 2026 | Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an… |
| CVE-2024-31947 | Media (6.5) | 0.73% | — | 12 jul 2024 | StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information. |
| CVE-2024-30213 | Alta (8.8) | 1.3% | — | 12 jul 2024 | StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution. |