Aller au contenu

Fiche vulnérabilité

CVE-2022-24552 : faille critique starwindsoftware nas (CVSS 9.8)

Description

A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges. This affects StarWind SAN and NAS v0.2 build 1633.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
6 févr. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • starwindsoftware nas
  • starwindsoftware san

Références

Rechercher une autre vulnérabilité dans la base CVE