← back
CVE-2021-32534criticalCWE-78

QSAN SANOS - Command Injection

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
In short

QSAN SANOS storage systems have a factory reset function that doesn't properly filter user input, allowing attackers to inject and run unauthorized commands on the device without needing special permissions.

Technical detail

CWE-78 command injection in the factory reset endpoint allows unauthenticated remote attackers to execute arbitrary OS commands by supplying malicious parameters; no input validation or sanitization is performed on the reset function parameters, resulting in complete system compromise.

Summary generated and translated by AI from the official description.
QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
QSAN · SANOS