Home

Description

Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.

PUBLISHED Reserved 2025-04-25 | Published 2025-04-25 | Updated 2025-04-25 | Assigner mitre




CRITICAL: 9.9CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-434 Unrestricted Upload of File with Dangerous Type

Product status

Default status
unaffected

Any version before 7.2.4
affected

References

www.quantum.com/...xt-gui-multiple-security-vulnerabilities/

cve.org (CVE-2025-46616)

nvd.nist.gov (CVE-2025-46616)

Download JSON