Vulnerabilities > Qsan > Storage Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-07-07 CVE-2021-32518 Link Following vulnerability in Qsan Storage Manager
A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbitrary files.
network
low complexity
qsan CWE-59
5.0
2021-07-07 CVE-2021-32519 Use of Password Hash With Insufficient Computational Effort vulnerability in Qsan Sanos, Storage Manager and Xevo
Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash.
network
low complexity
qsan CWE-916
5.0
2021-07-07 CVE-2021-32522 Improper Restriction of Excessive Authentication Attempts vulnerability in Qsan Sanos, Storage Manager and Xevo
Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack.
network
low complexity
qsan CWE-307
5.0
2021-07-07 CVE-2021-32523 Unspecified vulnerability in Qsan Storage Manager
Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary commands.
network
low complexity
qsan
6.5
2021-07-07 CVE-2021-32524 OS Command Injection vulnerability in Qsan Storage Manager
Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands.
network
low complexity
qsan CWE-78
6.5
2021-07-07 CVE-2021-32526 Incorrect Permission Assignment for Critical Resource vulnerability in Qsan Storage Manager
Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files.
network
low complexity
qsan CWE-732
4.0
2021-07-07 CVE-2021-32527 Path Traversal vulnerability in Qsan Storage Manager
Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files thru injecting file path in download function.
network
low complexity
qsan CWE-22
5.0
2021-07-07 CVE-2021-32528 Information Exposure Through Discrepancy vulnerability in Qsan Storage Manager
Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system information without permissions.
network
low complexity
qsan CWE-203
5.3