QSAN Storage Manager是广盛科技股份有限公司(QSAN)的一个NAS操作系统。 QSAN Storage Manager存在信任管理问题漏洞,该漏洞源于使用硬编码加密密钥漏洞使攻击者可利用该漏洞能够获得用户凭据和相关权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QSAN | Storage Manager | unspecified ~ 3.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32535 | 9.8 CRITICAL | QSAN SANOS - Use of Hard-coded Credentials |
| CVE-2021-32534 | 9.8 CRITICAL | QSAN SANOS - Command Injection |
| CVE-2021-32533 | 9.8 CRITICAL | QSAN SANOS - Command Injection |
| CVE-2021-32531 | 9.8 CRITICAL | QSAN XEVO - Command Injection Following via Init function |
| CVE-2021-32512 | 9.8 CRITICAL | QSAN Storage Manager - Command Injection Following via QuickInstall function |
| CVE-2021-32513 | 9.8 CRITICAL | QSAN Storage Manager - Command Injection Following via QsanTorture function |
| CVE-2021-32530 | 9.8 CRITICAL | QSAN XEVO - Command Injection Following via Array function |
| CVE-2021-32522 | 9.8 CRITICAL | QSAN Storage Manager, XEVO, SANOS - Improper Restriction of Excessive Authentication Attem |
| CVE-2021-32529 | 9.8 CRITICAL | QSAN XEVO, SANOS - Command Injection -1 |
| CVE-2021-32519 | 9.8 CRITICAL | QSAN Storage Manager, XEVO, SANOS - Use of Password Hash With Insufficient Computational E |
| CVE-2021-32525 | 9.1 CRITICAL | QSAN Storage Manager - Use of Hard-coded Password-2 |
| CVE-2021-32524 | 9.1 CRITICAL | QSAN Storage Manager - Command Injection-3 |
| CVE-2021-32523 | 9.1 CRITICAL | QSAN Storage Manager - Improper Authorization |
| CVE-2021-32527 | 7.5 HIGH | QSAN Storage Manager - Path Traversal-2 |
| CVE-2021-32518 | 7.5 HIGH | QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following |
| CVE-2021-32517 | 7.5 HIGH | QSAN Storage Manager - Improper Access Control |
| CVE-2021-32516 | 7.5 HIGH | QSAN Storage Manager - Path Traversal |
| CVE-2021-32514 | 7.5 HIGH | QSAN Storage Manager - Improper Access Control Following via FirwareUpgrade function |
| CVE-2021-32532 | 7.5 HIGH | QSAN XEVO - Path Traversal |
| CVE-2021-32521 | 7.3 HIGH | QSAN Storage Manager, XEVO, SANOS - Use of Hard-coded Password |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet