📦 Sanos

by Qsan

🔍 What is Sanos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-32535

CRITICAL CVSS 9.8 Jul 7, 2021

This vulnerability involves hard-coded default credentials in QSAN SANOS storage operating system, allowing unauthenticated remote attackers to gain administrator access and execute arbitrary commands...

CVE-2021-32519

CRITICAL CVSS 9.8 Jul 7, 2021

This vulnerability allows remote attackers to recover plain-text passwords by brute-forcing weak MD5 hashes in QSAN storage management systems. Attackers can potentially gain administrative access to ...

CVE-2021-32522

CRITICAL CVSS 9.8 Jul 7, 2021

This vulnerability allows remote attackers to perform brute force attacks against QSAN storage management systems due to insufficient authentication attempt restrictions. Attackers can discover valid ...

CVE-2021-32529

CRITICAL CVSS 9.8 Jul 7, 2021

This is a critical command injection vulnerability in QSAN XEVO and SANOS storage systems that allows remote unauthenticated attackers to execute arbitrary commands on affected devices. Attackers can ...

CVE-2021-32533

CRITICAL CVSS 9.8 Jul 7, 2021

CVE-2021-32533 is a critical OS command injection vulnerability in QSAN SANOS storage management software. Remote attackers can execute arbitrary commands without authentication by injecting special p...

CVE-2021-32521

HIGH CVSS 7.3 Jul 7, 2021

This vulnerability in QSAN Storage Manager, XEVO, and SANOS allows local attackers to escalate privileges by using the system's MAC address as an authenticated password. It affects organizations using...