VYPR

Command Center

by StarWind

CVEs (2)

  • CVE-2021-45389CriJan 4, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.

  • CVE-2022-23858HigJan 24, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects StarWind Command Center build 6003 v2.