PT-2022-16714 · Starwind · Starwind San/Nas

CVE-2022-24551

·

Published

2022-02-06

·

Updated

2022-09-01

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions StarWind SAN and NAS versions 0.2 build 1633 through 0.2 build 1684
Description A flaw was found in the password reset endpoint, which does not properly check the current username and old password. This allows an attacker to reset any local user password, including system or administrator user passwords, using any available user account.
Recommendations For StarWind SAN and NAS versions 0.2 build 1633 through 0.2 build 1684, update to version 0.2 build 1685 or later to resolve the issue. As a temporary workaround, consider restricting access to the password reset endpoint until the update can be applied.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24551

Affected Products

Starwind San/Nas