Starwind develops storage virtualization and management software for enterprise SAN and NAS environments, with its vulnerability footprint concentrating in the Command Center administrative interface and related storage products. The durable signal across its disclosures centers on improper authentication mechanisms, reflecting the access-control demands of centralized storage management platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Starwind over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45389CRITICAL A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This a | Jan 4, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Starwind.
Media articles that mention a CVE ID that affects a product developed by Starwind — matched by CVE ID, not by vendor name.