StoneFly Storage Concentrator Flaws Allow Unauthenticated Root Access
ID: 5d2cd5a4-77b8-550f-b589-464e8ae7a876
STIX ID: report--5d2cd5a4-77b8-550f-b589-464e8ae7a876
Feed Name: securityonline.info
A CISA advisory reports five critical vulnerabilities in StoneFly Storage Concentrator—including two unauthenticated remote root command-execution flaws (CVSS 10.0), an SQL injection exposing session tokens and secret keys, hardcoded credentials, and a reflected XSS—that affect multiple builds of the appliance and VM. The appliances are used in critical sectors (energy, healthcare, financial, defense), making compromise especially dangerous (backups wiped, ransomware, lateral movement); StoneFly recommends upgrading to 8.0.4.29+ and limiting network exposure until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
