Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html | Vendor Advisory |
https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html | Vendor Advisory |
Configurations
History
21 Nov 2024, 06:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html - Vendor Advisory |
02 Aug 2021, 12:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Suggest contacting with QSAN and refer to recommendations in QSAN Document. |
22 Jul 2021, 11:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3. |
10 Jul 2021, 03:02
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-732 | |
CPE | cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:* | |
References | (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 6.5 |
07 Jul 2021, 15:08
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-07-07 14:15
Updated : 2024-11-21 06:07
NVD link : CVE-2021-32526
Mitre link : CVE-2021-32526
CVE.ORG link : CVE-2021-32526
JSON object : View
Products Affected
qsan
- storage_manager
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource