CVE-2021-32520

CRITICAL

QSAN Storage Manager - Info Disclosure

Title source: llm
STIX 2.1

Description

Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4876-8da07-1.html

Scores

CVSS v3 9.8
EPSS 0.0103
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-321 CWE-798
Status published
Products (1)
qsan/storage_manager < 3.3.1
Published Jul 07, 2021
Tracked Since Feb 18, 2026