← back
CVE-2021-32523criticalCWE-285

QSAN Storage Manager - Improper Authorization

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.1epss 1.5%
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
In short

QSAN Storage Manager has a flaw that allows privileged remote users to bypass security controls and run any commands they want on the system. This is dangerous because attackers with admin access could take full control of the storage system.

Technical detail

The vulnerability involves improper authorization checks in QSAN Storage Manager, enabling authenticated privileged users to circumvent access control mechanisms and execute arbitrary commands. Attack vector is network-based requiring prior privileged credentials; impact includes complete system compromise and unauthorized command execution.

Summary generated and translated by AI from the official description.
Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
QSAN · Storage Manager