Junglewise Threat Intelligence

CVE-2026-56413: StoneFly Storage Concentrator command injection in ms_service.pl

CVE-2026-56413 · Severity: critical · CVSS 10 · Published 2026-06-30

Technologies: StoneFly Storage Concentrator, StoneFly Storage Concentrator Virtual Machine. Vendors: StoneFly.

Executive brief

StoneFly Storage Concentrator is a data storage management solution used to manage physical and virtual storage environments. A critical security flaw allows an unauthenticated attacker to remotely take full control of the device with the highest possible privileges. This could lead to the complete theft or destruction of stored data, disruption of business operations, and a total compromise of the storage infrastructure.

Technical details

A command injection vulnerability exists in the ms_service.pl service of StoneFly Storage Concentrator (SC) and Storage Concentrator Virtual Machine (SCVM). The service listens on TCP port 9000 by default and accepts custom network packets to perform device actions. Due to inadequate sanitization of these packets, an unauthenticated remote attacker can inject malicious payloads into OS commands. Successful exploitation allows for arbitrary command execution with root-level privileges. StoneFly recommends upgrading to version 8.0.4.29 or later to remediate this issue.

Affected products

  • StoneFly Storage Concentrator < 8.0.4.29
  • StoneFly Storage Concentrator Virtual Machine < 8.0.4.29

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory
  • 2026-06-30: patched: Version 8.0.4.29 released

References

Related threats