Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xn8024r Firmware MEDIUM 6.1
CVE-2021-37216

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch …

Mitigation only
Fix from $1,600 2021-08-02
Sanos CRITICAL 9.8
CVE-2021-32534

QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary com…

Fix: 2.1.0+
Fix from $2,300 2021-07-07
Sanos CRITICAL 9.8
CVE-2021-32535

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and ex…

Fix: 2.1.0+
Fix from $2,300 2021-07-07
Storage Manager CRITICAL 9.8
CVE-2021-32520

Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Sugg…

Fix: after 3.3.1
Fix from $2,300 2021-07-07
Sanos CRITICAL 9.8
CVE-2021-32521

Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contactin…

Fix: 1.2.0+
Fix from $2,300 2021-07-07
Sanos CRITICAL 9.8
CVE-2021-32522

Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover user…

Fix: 1.2.0+
Fix from $2,300 2021-07-07
Sanos CRITICAL 9.8
CVE-2021-32529

Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QS…

Fix: 1.2.0+
Fix from $2,300 2021-07-07
Xevo CRITICAL 9.8
CVE-2021-32530

OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status pa…

Fix: after 1.2.0
Fix from $2,300 2021-07-07
Xevo CRITICAL 9.8
CVE-2021-32531

OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The refer…

Fix: 2.1.0+
Fix from $2,300 2021-07-07
Sanos CRITICAL 9.8
CVE-2021-32533

The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands …

Fix: 2.1.0+
Fix from $2,300 2021-07-07
Sanos HIGH 7.5
CVE-2021-32519

Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the…

Fix: 2.1.0 / 3.3.2+
Fix from $1,950 2021-07-07
Storage Manager HIGH 7.5
CVE-2021-32527

Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files thru injecting file path in …

Fix: after 3.3.1
Fix from $1,950 2021-07-07
Xevo HIGH 7.5
CVE-2021-32532

Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary files without permissions. The …

Fix: 1.2.0+
Fix from $1,950 2021-07-07
Storage Manager HIGH 7.2
CVE-2021-32523

Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary comman…

Fix: after 3.3.1
Fix from $1,950 2021-07-07
Storage Manager HIGH 7.2
CVE-2021-32524

Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN an…

Fix: after 3.3.1
Fix from $1,950 2021-07-07
Storage Manager HIGH 7.2
CVE-2021-32525

The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator…

Fix: 3.3.1+
Fix from $1,950 2021-07-07
Storage Manager MEDIUM 6.5
CVE-2021-32526

Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary…

Fix: after 3.3.1
Fix from $1,600 2021-07-07
Storage Manager MEDIUM 5.3
CVE-2021-32528

Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system information without permissions.…

Fix: after 3.3.1
Fix from $1,600 2021-07-07
Storage Manager CRITICAL 9.8
CVE-2021-32512

QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute a…

Fix: 3.3.3+
Fix from $2,300 2021-07-07
Storage Manager CRITICAL 9.8
CVE-2021-32513

QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute ar…

Fix: 3.3.3+
Fix from $2,300 2021-07-07
Storage Manager HIGH 7.5
CVE-2021-32514

Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. The re…

Fix: 3.3.3+
Fix from $1,950 2021-07-07
Storage Manager HIGH 7.5
CVE-2021-32516

Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. The referred vulnerability ha…

Fix: 3.3.3+
Fix from $1,950 2021-07-07
Storage Manager HIGH 7.5
CVE-2021-32517

Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files using particular para…

Fix: 3.3.3+
Fix from $1,950 2021-07-07
Storage Manager HIGH 7.5
CVE-2021-32518

A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbitrary files. The referred vul…

Fix: 3.3.3+
Fix from $1,950 2021-07-07
Storage Manager MEDIUM 6.5
CVE-2021-32506

Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url …

Fix: 3.3.3+
Fix from $1,600 2021-07-07
Storage Manager MEDIUM 6.5
CVE-2021-32507

Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the …

Fix: 3.3.3+
Fix from $1,600 2021-07-07
Storage Manager MEDIUM 6.5
CVE-2021-32508

Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by inject…

Fix: 3.3.3+
Fix from $1,600 2021-07-07
Storage Manager MEDIUM 6.5
CVE-2021-32509

Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers access arbitrary files by injectin…

Fix: 3.3.3+
Fix from $1,600 2021-07-07
Storage Manager MEDIUM 5.3
CVE-2021-32515

Directory listing vulnerability in share_link in QSAN Storage Manager allows attackers to list arbitrary directories and further access credential in…

Fix: 3.3.3+
Fix from $1,600 2021-07-07