Vulnerability Description
Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qsan | Sanos | <= 2.0.0 |
| Qsan | Storage Manager | <= 3.3.1 |
| Qsan | Xevo | < 1.2.0 |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-4878-0a279-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4878-0a279-1.htmlThird Party Advisory
FAQ
What is CVE-2021-32522?
CVE-2021-32522 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force ...
How severe is CVE-2021-32522?
CVE-2021-32522 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-32522?
Check the references section above for vendor advisories and patch information. Affected products include: Qsan Sanos, Qsan Storage Manager, Qsan Xevo.