CVE-2026-56413 Details
Description
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges.
A command injection vulnerability has been identified in the StoneFly Storage Concentrator (both SC and SCVM) ms_service.pl service, which operates on TCP port 9000 by default. This vulnerability allows unauthenticated remote attackers to send specially crafted packets containing malicious payloads that are executed with root privileges, due to inadequate input sanitization.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| StoneFly Storage Concentrator | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
| StoneFly Storage Concentrator Virtual Machine | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion