CVE-2022-24551
06.02.2022, 21:15
A flaw was found in StarWind Stack. The endpoint for setting a new password doesnt check the current username and old password. An attacker could reset any local user password (including system/administrator user) using any available user This affects StarWind SAN and NAS v0.2 build 1633.Enginsight
Vendor | Product | Version |
---|---|---|
starwindsoftware | nas | 𝑥 < 0.2 |
starwindsoftware | san | 𝑥 < 0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration