CVE-2021-32520

Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-4876-8da07-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:*

History

21 Sep 2021, 16:14

Type Values Removed Values Added
CWE CWE-798 CWE-321

22 Jul 2021, 11:15

Type Values Removed Values Added
Summary Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

10 Jul 2021, 03:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:*
CWE CWE-798
References (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4876-8da07-1.html - (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4876-8da07-1.html - Third Party Advisory

07 Jul 2021, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-07 14:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-32520

Mitre link : CVE-2021-32520

CVE.ORG link : CVE-2021-32520


JSON object : View

Products Affected

qsan

  • storage_manager
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-798

Use of Hard-coded Credentials