CVE-2024-30213: Command Injection
Published Jul 12, 2024
·Updated
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.
Affected Software
1 affected component
StoneFly Storage Concentrator<8.0.4.26
Event History
Jul 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30213?
CVE-2024-30213 has a high severity rating of 8.8 according to the CVSS 3.1 scoring system.
2
What type of vulnerability is identified in CVE-2024-30213?
CVE-2024-30213 is classified as a Command Injection vulnerability.
3
How do I fix CVE-2024-30213?
To fix CVE-2024-30213, upgrade the StoneFly Storage Concentrator to version 8.0.4.26 or later.
4
What are the potential consequences of CVE-2024-30213?
CVE-2024-30213 could lead to remote code execution if exploited by an attacker.
5
Who is affected by CVE-2024-30213?
CVE-2024-30213 affects users of StoneFly Storage Concentrator versions prior to 8.0.4.26.