CVE-2026-50110
StoneFly Storage Concentrator, Storage Concentrator Virtual Machine 취약점
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of internal services, including database accounts, licensing, replication services, and third-party integrations, meaning successful exploitation of this vulnerability could provide an attacker with unauthorized access to multiple interconnected systems.
- 대응 우선순위
- 점검
- CVSS
- 9.3
- EPSS
- 0.14% 백분위 3.90% · 2026.07.31 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.01