Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Starwindsoftware

First CVE: Apr 10, 2018Active for: 8 yearsTotal CVEs: 30
58.4
VTI Score
TOP TARGET

Starwindsoftware develops storage virtualization and SAN/NAS infrastructure products that consolidate and manage block and file storage across enterprise environments. Its vulnerability footprint, though concentrated in a small product family, reaches a more prominent position in the landscape owing to the mission-critical role these appliances play in data center architectures. The recurring exposure centers on the vendor's core virtual SAN, command-and-control, and iSCSI platforms and clusters around memory-safety issues such as out-of-bounds reads and writes, use-after-free conditions, and authentication and command-injection weaknesses that are characteristic of systems-level software handling network protocols and storage access. Vulnerabilities affecting this vendor show a moderate tendency toward serious severity outcomes, reflecting the access and privilege context in which these flaws operate. Defenders should inventory Starwindsoftware deployments in their environments and prioritize patching given the central role these platforms occupy; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
3.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Starwindsoftware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2018
8 years ago
Most Recent CVE
Jun 3, 2022
1,512 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-4034HIGH
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri
Jan 28, 20227.898YESYES
CVE-2021-43527CRITICAL
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS f
Dec 8, 20219.841NONO
CVE-2021-42574HIGH
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be
Nov 1, 20218.335NONO
CVE-2022-24552CRITICAL
A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a sc
Feb 6, 20229.831NONO
CVE-2022-32268HIGH
StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostname, doesn’t check a
Jun 3, 20228.829NONO
CVE-2013-20004CRITICAL
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of
Feb 6, 20229.829NONO
CVE-2018-3839HIGH
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an
Apr 10, 20188.829NONO
CVE-2022-24551HIGH
A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (in
Feb 6, 20228.828NONO
CVE-2022-23858HIGH
A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects StarWind Command Cent
Jan 24, 20228.828NONO
CVE-2021-41617HIGH
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expecte
Sep 26, 20217.027NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
43%
43%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (46.7%)
Network16 (53.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (80.0%)
High6 (20.0%)
Unknown0 (0.0%)
User Interaction
None22 (73.3%)
Unknown0 (0.0%)
Required8 (26.7%)
Privileges Required
Low12 (40.0%)
High3 (10.0%)
None15 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
1 CVE
3.3% of CVEs· 99th percentile
Metasploit
1 CVE
3.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Starwindsoftware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Starwindsoftware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Starwindsoftware's Products

View all 5 CNAs →

Top CWEs