CVE-2021-32525

CRITICAL

QSAN Storage Manager <3.3.3 - RCE

Title source: llm
STIX 2.1

Description

The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

Scores

CVSS v3 9.1
EPSS 0.0096
EPSS Percentile 76.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-259 CWE-798
Status published
Products (1)
qsan/storage_manager < 3.3.1
Published Jul 07, 2021
Tracked Since Feb 18, 2026