Quantum's vulnerability profile centers on its Scalar i500 backup and archive appliance and associated firmware, which present a web-facing management interface susceptible to application-layer flaws. The recurring weakness classes include cross-site request forgery, path traversal, cross-site scripting, and OS command injection, reflecting common vulnerabilities in embedded web management consoles. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quantum over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1844HIGH The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the | Mar 22, 2012 | 7.5 | 25 | NO | NO |
CVE-2014-2959HIGH logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS | Jun 2, 2014 | 9.0 | 23 | NO | NO |
CVE-2012-1843MEDIUM Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell | Mar 22, 2012 | 6.0 | 21 | NO | NO |
CVE-2012-1841MEDIUM Absolute path traversal vulnerability in logShow.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape li | Mar 22, 2012 | 5.0 | 19 | NO | NO |
Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 | Mar 22, 2012 | 3.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quantum.
Media articles that mention a CVE ID that affects a product developed by Quantum — matched by CVE ID, not by vendor name.