PT-2025-17892 · Quantum · Activescale Cold Storage+2

·

CVE-2025-46617

·

Published

2025-04-25

·

Updated

2025-07-01

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions StorNext RYO versions prior to 7.2.4 StorNext Xcellis Workflow Director versions prior to 7.2.4 ActiveScale Cold Storage versions prior to 7.2.4
Description The issue allows access to internal configuration and unauthorized modification of software configuration parameters via undocumented user credentials.
Recommendations For StorNext RYO versions prior to 7.2.4, update to version 7.2.4 or later. For StorNext Xcellis Workflow Director versions prior to 7.2.4, update to version 7.2.4 or later. For ActiveScale Cold Storage versions prior to 7.2.4, update to version 7.2.4 or later.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-46617

Affected Products

Activescale Cold Storage
Stornext Ryo
Stornext Xcellis Workflow Director