More Like This
-
Capability Overview
Cyber Resilience
-
Product / Service
Penetration Testing Services
Aon discovered two security vulnerabilities affecting StoneFly Storage Concentrator (SC) and Storage Concentrator Virtual Machine (SCVM) leading to arbitrary command execution and information disclosure, both requiring user authentication. The vulnerabilities affect SC and SCVM running version 8.0.4.25 and below. The vulnerabilities were discovered by Aon team member David Glenn Baylon.
Aon would like to thank StoneFly for working with us as part of our coordinated disclosure process.
Capability Overview
Cyber Resilience
Product / Service
Penetration Testing Services
StoneFly SC and SCVM are vulnerable to authenticated blind operating system command injection attacks. Successful exploitation of this vulnerability leads to privileged arbitrary command execution, resulting in complete compromise of an SC and/or SCVM.
Refer to the vendor pages listed under Vendor Advisory for a complete list of product versions in which this vulnerability has been fixed and further instructions on how to upgrade the affected systems.
StoneFly SC and SCVM are vulnerable to authenticated path traversal attacks. Successful exploitation of this vulnerability leads to disclosure of sensitive information.
Refer to the vendor pages listed under Vendor Advisory for a complete list of product versions in which this vulnerability has been fixed and further instructions on how to upgrade the affected systems.
Support
About Cyber Solutions:
Aon’s Cyber Solutions offers holistic cyber risk management, unsurpassed investigative skills, and proprietary technologies to help clients uncover and quantify cyber risks, protect critical assets, and recover from cyber incidents.
General Disclaimer
This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.
Terms of Use
The contents herein may not be reproduced, reused, reprinted or redistributed without the expressed written consent of Aon, unless otherwise authorized by Aon. To use information contained herein, please write to our team.
Our Better Being podcast series, hosted by Aon Chief Wellbeing Officer Rachel Fellowes, explores wellbeing strategies and resilience. This season we cover human sustainability, kindness in the workplace, how to measure wellbeing, managing grief and more.
Expert Views on Today's Risk Capital and Human Capital Issues
Expert Views on Today's Risk Capital and Human Capital Issues
Expert Views on Today's Risk Capital and Human Capital Issues
The construction industry is under pressure from interconnected risks and notable macroeconomic developments. Learn how your organization can benefit from construction insurance and risk management.
Stay in the loop on today's most pressing cyber security matters.
Our Cyber Resilience collection gives you access to Aon’s latest insights on the evolving landscape of cyber threats and risk mitigation measures. Reach out to our experts to discuss how to make the right decisions to strengthen your organization’s cyber resilience.
Our Employee Wellbeing collection gives you access to the latest insights from Aon's human capital team. You can also reach out to the team at any time for assistance with your employee wellbeing needs.
Explore Aon's latest environmental social and governance (ESG) insights.
Our Global Insurance Market Insights highlight insurance market trends across pricing, capacity, underwriting, limits, deductibles and coverages.
How do the top risks on business leaders’ minds differ by region and how can these risks be mitigated? Explore the regional results to learn more.