Starwindsoftware develops storage virtualization and SAN/NAS infrastructure products that consolidate and manage block and file storage across enterprise environments. Its vulnerability footprint, though concentrated in a small product family, reaches a more prominent position in the landscape owing to the mission-critical role these appliances play in data center architectures. The recurring exposure centers on the vendor's core virtual SAN, command-and-control, and iSCSI platforms and clusters around memory-safety issues such as out-of-bounds reads and writes, use-after-free conditions, and authentication and command-injection weaknesses that are characteristic of systems-level software handling network protocols and storage access. Vulnerabilities affecting this vendor show a moderate tendency toward serious severity outcomes, reflecting the access and privilege context in which these flaws operate. Defenders should inventory Starwindsoftware deployments in their environments and prioritize patching given the central role these platforms occupy; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Starwindsoftware over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4034HIGH A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri | Jan 28, 2022 | 7.8 | 98 | YES | YES |
CVE-2021-43527CRITICAL NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS f | Dec 8, 2021 | 9.8 | 41 | NO | NO |
CVE-2021-42574HIGH An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be | Nov 1, 2021 | 8.3 | 35 | NO | NO |
CVE-2022-24552CRITICAL A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a sc | Feb 6, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-32268HIGH StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostname, doesn’t check a | Jun 3, 2022 | 8.8 | 29 | NO | NO |
CVE-2013-20004CRITICAL A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of | Feb 6, 2022 | 9.8 | 29 | NO | NO |
CVE-2018-3839HIGH An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an | Apr 10, 2018 | 8.8 | 29 | NO | NO |
CVE-2022-24551HIGH A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (in | Feb 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-23858HIGH A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects StarWind Command Cent | Jan 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-41617HIGH sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expecte | Sep 26, 2021 | 7.0 | 27 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Starwindsoftware.
Media articles that mention a CVE ID that affects a product developed by Starwindsoftware — matched by CVE ID, not by vendor name.