StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.
References
Configurations
No configuration.
History
21 Nov 2024, 09:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://stonefly.com/security-advisories/cve-2024-30213/ - | |
References | () https://www.stonefly.com/services - |
01 Aug 2024, 13:50
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | CWE-77 |
15 Jul 2024, 13:00
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
12 Jul 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-12 23:15
Updated : 2024-11-21 09:11
NVD link : CVE-2024-30213
Mitre link : CVE-2024-30213
CVE.ORG link : CVE-2024-30213
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')