CVE-2022-24551

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
06/02/2022
Last modified:
01/09/2022

Description

A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (including system/administrator user) using any available user This affects StarWind SAN and NAS v0.2 build 1633.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:starwindsoftware:nas:*:*:*:*:*:*:*:* 0.2 (excluding)
cpe:2.3:a:starwindsoftware:san:*:*:*:*:*:*:*:* 0.2 (excluding)


References to Advisories, Solutions, and Tools