ICSCISA-advisorystoragehardcoded-credentialscommand-injectionsql-injectionxssunauthenticated-RCEroot-accesscritical-infrastructure
StoneFly Storage Concentrator (SC) and its Virtual Machine variant contain five critical/medium vulnerabilities including hardcoded credentials, two unauthenticated OS command injection flaws leading to root-level remote code execution, an unauthenticated SQL injection exposing session tokens and password hashes, and a reflected XSS. Combined, these flaws allow attackers to fully compromise storage infrastructure without authentication, potentially affecting Defense Industrial Base, Energy, Financial Services, Healthcare, and IT sector organizations worldwide.
Updated Jul 6, 2026 · CVSS 10