StoneFly Storage Concentrator
Multiple critical vulnerabilities in StoneFly Storage Concentrator versions prior to 8.0.4.29 allow unauthenticated remote attackers to gain unauthorized access and execute arbitrary commands with root privileges. The vulnerabilities include hardcoded credentials (CWE-798), OS command injection (CWE-78), SQL injection (CWE-89), and cross-site scripting (CWE-79). Successful exploitation enables attackers to steal sensitive data, compromise the appliance, and potentially access interconnected systems. Both physical Storage Concentrator appliances and Virtual Machine deployments are affected.
- Network access to the Storage Concentrator's management interface (default port 443 or configured HTTPS port)
- No authentication required due to hardcoded credentials or input validation bypass
Patching may require device reboot — plan for process interruption
/api/v1/advisories/9e55b207-6332-491a-8d3d-a9d534cf9f20Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.