Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
References
Configurations
No configuration.
History
29 Apr 2025, 13:52
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Apr 2025, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-25 07:15
Updated : 2025-04-29 13:52
NVD link : CVE-2025-46617
Mitre link : CVE-2025-46617
CVE.ORG link : CVE-2025-46617
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials