📦 Xevo

by Qsan

🔍 What is Xevo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-32519

CRITICAL CVSS 9.8 Jul 7, 2021

This vulnerability allows remote attackers to recover plain-text passwords by brute-forcing weak MD5 hashes in QSAN storage management systems. Attackers can potentially gain administrative access to ...

CVE-2021-32522

CRITICAL CVSS 9.8 Jul 7, 2021

This vulnerability allows remote attackers to perform brute force attacks against QSAN storage management systems due to insufficient authentication attempt restrictions. Attackers can discover valid ...

CVE-2021-32529

CRITICAL CVSS 9.8 Jul 7, 2021

This is a critical command injection vulnerability in QSAN XEVO and SANOS storage systems that allows remote unauthenticated attackers to execute arbitrary commands on affected devices. Attackers can ...

CVE-2021-32531

CRITICAL CVSS 9.8 Jul 7, 2021

This CVE describes an OS command injection vulnerability in QSAN XEVO storage management software that allows remote attackers to execute arbitrary commands without authentication. Attackers can gain ...

CVE-2021-32521

HIGH CVSS 7.3 Jul 7, 2021

This vulnerability in QSAN Storage Manager, XEVO, and SANOS allows local attackers to escalate privileges by using the system's MAC address as an authenticated password. It affects organizations using...