StoneFly Storage Concentrator

Plan PatchCVSS 10ICS-CERT ICSA-26-181-06Jun 30, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Multiple critical vulnerabilities in StoneFly Storage Concentrator versions prior to 8.0.4.29 allow unauthenticated remote attackers to gain unauthorized access and execute arbitrary commands with root privileges. The vulnerabilities include hardcoded credentials (CWE-798), OS command injection (CWE-78), SQL injection (CWE-89), and cross-site scripting (CWE-79). Successful exploitation enables attackers to steal sensitive data, compromise the appliance, and potentially access interconnected systems. Both physical Storage Concentrator appliances and Virtual Machine deployments are affected.

What this means
What could happen
An attacker could gain complete control of the Storage Concentrator, executing commands with root privileges, accessing sensitive data, and potentially compromising any systems connected to it through the storage infrastructure.
Who's at risk
Water authorities, electric utilities, and other critical infrastructure operators using StoneFly Storage Concentrator appliances for data storage and backup should prioritize this update. The vulnerability affects both physical appliances and virtual machine deployments used for backup, archival, and disaster recovery operations.
How it could be exploited
An attacker on the network can send specially crafted requests to the Storage Concentrator's web interface or API (CWE-798 hardcoded credentials, CWE-89 SQL injection, CWE-79 XSS, CWE-78 OS command injection). These vulnerabilities allow the attacker to bypass authentication and execute arbitrary OS commands with root privileges on the appliance.
Prerequisites
  • Network access to the Storage Concentrator's management interface (default port 443 or configured HTTPS port)
  • No authentication required due to hardcoded credentials or input validation bypass
remotely exploitableno authentication requiredlow complexityaffects critical infrastructure systemsallows root command executionenables lateral movement to connected systems
Exploitability
Some exploitation risk — EPSS score 4.4%
Affected products (6)
3 with fix3 pending
ProductAffected VersionsFix Status
Storage Concentrator<8.0.4.26Fix available
Storage Concentrator<8.0.4.29Fix available
Storage Concentrator<8.0.4.22Fix available
Storage Concentrator Virtual Machine<8.0.4.26No fix yet
Storage Concentrator Virtual Machine<8.0.4.29No fix yet
Storage Concentrator Virtual Machine<8.0.4.22No fix yet
Remediation & Mitigation
0/4
Do now
0/1
Storage Concentrator
WORKAROUNDRestrict network access to the Storage Concentrator management interface to authorized administrative networks only using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Storage Concentrator
HOTFIXUpdate Storage Concentrator to version 8.0.4.29 or later
Long-term hardening
0/2
Storage Concentrator
HARDENINGImplement network-based monitoring and logging of all connections to the Storage Concentrator management interface
All products
HARDENINGSegment storage infrastructure onto a dedicated VLAN separate from operational technology networks and general IT networks
API: /api/v1/advisories/9e55b207-6332-491a-8d3d-a9d534cf9f20

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.