SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-37216

Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

MEDIUM 6.1EPSS 3.16%

Does this matter?

Lower severity and a low EPSS score (3.16%). Track it; it rarely justifies an emergency change on its own.

Description

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
3.16% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
qsan/xn8024r firmware · qsan/xn8008t firmware
Source
twcert@cert.org.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.