CVE-2021-32520

Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
Configurations

Configuration 1 (hide)

cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:07

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-4876-8da07-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-4876-8da07-1.html - Third Party Advisory

21 Sep 2021, 16:14

Type Values Removed Values Added
CWE CWE-798 CWE-321

22 Jul 2021, 11:15

Type Values Removed Values Added
Summary Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

10 Jul 2021, 03:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : 7.5
v3 : 9.8
References (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4876-8da07-1.html - (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4876-8da07-1.html - Third Party Advisory
CWE CWE-798
CPE cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:*

07 Jul 2021, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-07 14:15

Updated : 2024-11-21 06:07


NVD link : CVE-2021-32520

Mitre link : CVE-2021-32520

CVE.ORG link : CVE-2021-32520


JSON object : View

Products Affected

qsan

  • storage_manager
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-798

Use of Hard-coded Credentials