Executive brief
StoneFly Storage Concentrator, a solution used for managing enterprise data storage, is vulnerable to a security flaw that allows unauthorized individuals to access its internal database. By sending specially crafted web requests, an attacker can steal sensitive information such as login credentials, session tokens, and secret keys. This could lead to a full compromise of the storage management system and the data it protects.
Technical details
A SQL injection vulnerability exists in StoneFly Storage Concentrator (SC) and Storage Concentrator Virtual Machine (SCVM) within the 'login.pl' and 'debug.pl' scripts. The vulnerability is caused by the direct incorporation of HTTP cookie values into database queries without sufficient sanitization. An unauthenticated remote attacker can exploit this by providing malicious SQL commands within a cookie, enabling the extraction of sensitive data including session tokens, password hashes, and secret keys. The issue is addressed in version 8.0.4.29 and later.
Affected products
- StoneFly Storage Concentrator < 8.0.4.22
- StoneFly Storage Concentrator Virtual Machine < 8.0.4.22
Timeline
- 2026-06-30: advisory: CISA ICSA-26-181-06 published
- 2026-06-30: disclosed: CVE-2026-55721 published to NVD