As cited
Copy frozen at (site build).
vulnerabilities
StoneFly Storage Concentrator
StoneFly Storage Concentrator contains multiple critical vulnerabilities including hardcoded credentials, OS command injection, SQL injection, and cross-site scripting affecting versions before 8.0.4.29. An unauthenticated attacker can exploit these flaws to execute arbitrary commands with root privileges, access interconnected systems, and steal sensitive data. StoneFly recommends immediate upgrade to version 8.0.4.29 or later.
Why it matters: Multiple CVSS 10 vulnerabilities with unauthenticated remote root execution require immediate patching, especially given deployment across critical infrastructure sectors worldwide.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
StoneFly Storage Concentrator
StoneFly Storage Concentrator contains multiple critical vulnerabilities including hardcoded credentials, OS command injection, SQL injection, and cross-site scripting affecting versions before 8.0.4.29. An unauthenticated attacker can exploit these flaws to execute arbitrary commands with root privileges, access interconnected systems, and steal sensitive data. StoneFly recommends immediate upgrade to version 8.0.4.29 or later.
Why it matters: Multiple CVSS 10 vulnerabilities with unauthenticated remote root execution require immediate patching, especially given deployment across critical infrastructure sectors worldwide.
- Source published
- First seen by Cybersecurity Tracker