Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 7.2.4
affected
Description
Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
Any version before 7.2.4
References
www.quantum.com/...xt-gui-multiple-security-vulnerabilities/