QSAN SANOS是中国QSAN公司的SAN 存储管理操作系统。它配备了令人耳目一新的简单易用的 Web GUI,并且可以轻松部署到任何基础架构中。 QSAN SANOS 存在操作系统命令注入漏洞,该漏洞源于QSAN SANOS恢复出厂设置功能不过滤特殊参数。攻击者可利用该漏洞注入和执行没有权限的任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32520 | 9.8 CRITICAL | QSAN Storage Manager - Use of Hard-coded Cryptographic Key |
| CVE-2021-32535 | 9.8 CRITICAL | QSAN SANOS - Use of Hard-coded Credentials |
| CVE-2021-32533 | 9.8 CRITICAL | QSAN SANOS - Command Injection |
| CVE-2021-32531 | 9.8 CRITICAL | QSAN XEVO - Command Injection Following via Init function |
| CVE-2021-32530 | 9.8 CRITICAL | QSAN XEVO - Command Injection Following via Array function |
| CVE-2021-32529 | 9.8 CRITICAL | QSAN XEVO, SANOS - Command Injection -1 |
| CVE-2021-32522 | 9.8 CRITICAL | QSAN Storage Manager, XEVO, SANOS - Improper Restriction of Excessive Authentication Attem |
| CVE-2021-32519 | 9.8 CRITICAL | QSAN Storage Manager, XEVO, SANOS - Use of Password Hash With Insufficient Computational E |
| CVE-2021-32513 | 9.8 CRITICAL | QSAN Storage Manager - Command Injection Following via QsanTorture function |
| CVE-2021-32512 | 9.8 CRITICAL | QSAN Storage Manager - Command Injection Following via QuickInstall function |
| CVE-2021-32523 | 9.1 CRITICAL | QSAN Storage Manager - Improper Authorization |
| CVE-2021-32524 | 9.1 CRITICAL | QSAN Storage Manager - Command Injection-3 |
| CVE-2021-32525 | 9.1 CRITICAL | QSAN Storage Manager - Use of Hard-coded Password-2 |
| CVE-2021-32514 | 7.5 HIGH | QSAN Storage Manager - Improper Access Control Following via FirwareUpgrade function |
| CVE-2021-32516 | 7.5 HIGH | QSAN Storage Manager - Path Traversal |
| CVE-2021-32517 | 7.5 HIGH | QSAN Storage Manager - Improper Access Control |
| CVE-2021-32518 | 7.5 HIGH | QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following |
| CVE-2021-32532 | 7.5 HIGH | QSAN XEVO - Path Traversal |
| CVE-2021-32527 | 7.5 HIGH | QSAN Storage Manager - Path Traversal-2 |
| CVE-2021-32521 | 7.3 HIGH | QSAN Storage Manager, XEVO, SANOS - Use of Hard-coded Password |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet