CVE-2021-32526

Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:*

History

02 Aug 2021, 12:15

Type Values Removed Values Added
Summary Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3. Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

22 Jul 2021, 11:15

Type Values Removed Values Added
Summary Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary password files. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

10 Jul 2021, 03:02

Type Values Removed Values Added
CPE cpe:2.3:a:qsan:storage_manager:*:*:*:*:*:*:*:*
CWE CWE-732
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5
References (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html - (CONFIRM) https://www.twcert.org.tw/tw/cp-132-4882-c0310-1.html - Vendor Advisory

07 Jul 2021, 15:08

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-07 14:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-32526

Mitre link : CVE-2021-32526

CVE.ORG link : CVE-2021-32526


JSON object : View

Products Affected

qsan

  • storage_manager
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource