LevelBlue Completes Acquisition of Cybereason. Learn more
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
LevelBlue Completes Acquisition of Cybereason. Learn more
Stroz Friedberg discovered two security vulnerabilities affecting StoneFly Storage Concentrator (SC) and Storage Concentrator Virtual Machine (SCVM) leading to arbitrary command execution and information disclosure, both requiring user authentication. The vulnerabilities affect SC and SCVM running version 8.0.4.25 and below. The vulnerabilities were discovered by Stroz Friedberg team member David Glenn Baylon.
Stroz Friedberg would like to thank StoneFly for working with us as part of our coordinated disclosure process.
StoneFly SC and SCVM are vulnerable to authenticated blind operating system command injection attacks. Successful exploitation of this vulnerability leads to privileged arbitrary command execution, resulting in complete compromise of an SC and/or SCVM.
Refer to the vendor pages listed under Vendor Advisory for a complete list of product versions in which this vulnerability has been fixed and further instructions on how to upgrade the affected systems.
StoneFly SC and SCVM are vulnerable to authenticated path traversal attacks. Successful exploitation of this vulnerability leads to disclosure of sensitive information.
Refer to the vendor pages listed under Vendor Advisory for a complete list of product versions in which this vulnerability has been fixed and further instructions on how to upgrade the affected systems.
LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.