QSAN XEVO是中国QSAN公司的一款闪存数据管理系统。减少重复性任务并提供完整的数据分析。 QSAN XEVO 中存在路径遍历漏洞,该漏洞源于产品的back-end分析函数未能过滤输入数据的特殊字符。攻击者可通过该漏洞在没有权限的情况下下载任意文件。 QSAN XEVO后端分析功能存在路径遍历漏洞,允许远程攻击者可利用该漏洞下载任意文件而无需权限。以下产品及版本受到影响:QSAN XEVO 1.2.0 (build 202007081800) 之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32520 | 9.8 CRITICAL | QSAN Storage Manager - Use of Hard-coded Cryptographic Key |
| CVE-2021-32535 | 9.8 CRITICAL | QSAN SANOS - Use of Hard-coded Credentials |
| CVE-2021-32534 | 9.8 CRITICAL | QSAN SANOS - Command Injection |
| CVE-2021-32533 | 9.8 CRITICAL | QSAN SANOS - Command Injection |
| CVE-2021-32531 | 9.8 CRITICAL | QSAN XEVO - Command Injection Following via Init function |
| CVE-2021-32530 | 9.8 CRITICAL | QSAN XEVO - Command Injection Following via Array function |
| CVE-2021-32529 | 9.8 CRITICAL | QSAN XEVO, SANOS - Command Injection -1 |
| CVE-2021-32522 | 9.8 CRITICAL | QSAN Storage Manager, XEVO, SANOS - Improper Restriction of Excessive Authentication Attem |
| CVE-2021-32519 | 9.8 CRITICAL | QSAN Storage Manager, XEVO, SANOS - Use of Password Hash With Insufficient Computational E |
| CVE-2021-32512 | 9.8 CRITICAL | QSAN Storage Manager - Command Injection Following via QuickInstall function |
| CVE-2021-32513 | 9.8 CRITICAL | QSAN Storage Manager - Command Injection Following via QsanTorture function |
| CVE-2021-32525 | 9.1 CRITICAL | QSAN Storage Manager - Use of Hard-coded Password-2 |
| CVE-2021-32524 | 9.1 CRITICAL | QSAN Storage Manager - Command Injection-3 |
| CVE-2021-32523 | 9.1 CRITICAL | QSAN Storage Manager - Improper Authorization |
| CVE-2021-32516 | 7.5 HIGH | QSAN Storage Manager - Path Traversal |
| CVE-2021-32527 | 7.5 HIGH | QSAN Storage Manager - Path Traversal-2 |
| CVE-2021-32514 | 7.5 HIGH | QSAN Storage Manager - Improper Access Control Following via FirwareUpgrade function |
| CVE-2021-32518 | 7.5 HIGH | QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following |
| CVE-2021-32517 | 7.5 HIGH | QSAN Storage Manager - Improper Access Control |
| CVE-2021-32521 | 7.3 HIGH | QSAN Storage Manager, XEVO, SANOS - Use of Hard-coded Password |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet