AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-24552

CRITICAL · CVSS 9.8 EPSS 1.31%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-02-06 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. See the original NVD description below for full technical details.

CVE
CVE-2022-24552
Severity
CRITICAL
CVSS
9.8
EPSS
1.31%

Original NVD Description

A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges. This affects StarWind SAN and NAS v0.2 build 1633.

Related CVEs

Other vulnerabilities affecting the same vendor(s)