Impact
The StoneFly Storage Concentrator and its virtual machine contain an OS command injection flaw in the debug.pl script. The vulnerability is reachable without authentication; a remote attacker can send a specially crafted HTTP request that is processed without proper input sanitization, leading to arbitrary command execution with root privileges on the underlying operating system. The weakness is identified as CWE-78.
Affected Systems
Both the StoneFly Storage Concentrator hardware appliance and the Storage Concentrator Virtual Machine are affected in versions prior to 8.0.4.29; the vulnerability is fixed by upgrading to version 8.0.4.29 or later. No additional version specifics are provided.
Risk and Exploitability
The CVSS score of 10 indicates a critical risk level. No authentication is required and the flaw can be triggered with a single HTTP request, so the attack vector is remote, unauthenticated, and highly attackable. The EPSS score of 3% indicates a low probability of exploitation in real-world scenarios, implying that while the technical conditions for an attack are simple, the likelihood of the vulnerability being actively used by threat actors remains modest. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment