← back
CVE-2021-32529criticalCWE-77

QSAN XEVO, SANOS - Command Injection -1

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 2.3%
exploitation probability
2.3%top 19% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in QSAN XEVO and SANOS storage systems allows attackers to run unauthorized commands without logging in. This puts your data and system completely at risk.

Technical detail

Remote unauthenticated command injection vulnerability in QSAN XEVO and SANOS storage systems (CWE-77) permits arbitrary command execution via unsanitized input. No authentication required; attacker can directly compromise system integrity and confidentiality. CVSS 9.8 reflects critical severity with network accessibility and no user interaction required.

Summary generated and translated by AI from the official description.
Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
QSAN · SANOSQSAN · XEVO