StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.
References
Configurations
No configuration.
History
21 Nov 2024, 09:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://stonefly.com/security-advisories/cve-2024-30213/ - | |
| References | () https://www.stonefly.com/services - |
01 Aug 2024, 13:50
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-77 |
15 Jul 2024, 13:00
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
12 Jul 2024, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-07-12 23:15
Updated : 2024-11-21 09:11
NVD link : CVE-2024-30213
Mitre link : CVE-2024-30213
CVE.ORG link : CVE-2024-30213
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
