CVE-2021-32526

Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
Configurations

Configuration 1 (hide)

cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:07

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html - Vendor Advisory () https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html - Vendor Advisory

02 Aug 2021, 12:15

Type Values Removed Values Added
Summary Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3. Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

22 Jul 2021, 11:15

Type Values Removed Values Added
Summary Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

10 Jul 2021, 03:02

Type Values Removed Values Added
CWE CWE-732
CPE cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:*
References (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html - (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5

07 Jul 2021, 15:08

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-07 14:15

Updated : 2024-11-21 06:07


NVD link : CVE-2021-32526

Mitre link : CVE-2021-32526

CVE.ORG link : CVE-2021-32526


JSON object : View

Products Affected

qsan

  • storage_manager
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource