vuln-advisoryregulatorNewsThe Broadside1 min read

CISA flags CVSS 10 StoneFly Storage Concentrator flaws

For contractors, this is an exposure-management item: find SC and SCVM instances and move them to 8.0.4.29 or later.


TL;DR

CISA published an ICS advisory for StoneFly Storage Concentrator and Storage Concentrator Virtual Machine covering five vulnerabilities, including CVSS 10 unauthenticated command injection flaws in versions before 8.0.4.22 and 8.0.4.29. Defense industrial base, energy, financial services, healthcare, and information technology operators should patch to 8.0.4.29 or later. The credential issue spans database, licensing, replication, and third-party integration accounts stored in reversible encoded form.

CISA’s advisory puts the operational answer in one place: StoneFly Storage Concentrator and Storage Concentrator Virtual Machine users should upgrade to version 8.0.4.29 or later. The affected versions are split across the flaw set: versions before 8.0.4.22 for CVE-2026-56415, CVE-2026-55721, and CVE-2026-50040, versions before 8.0.4.26 for CVE-2026-50110, and versions before 8.0.4.29 for CVE-2026-56413.

The highest-risk findings are the two unauthenticated command injection vulnerabilities. CVE-2026-56413 affects the ms_service.pl service, which listens on TCP port 9000 by default, and can allow arbitrary command execution with root-level privileges. CVE-2026-56415 affects the debug.pl script and can also allow unauthenticated remote command execution as root.

CISA also lists CVE-2026-55721, an unauthenticated SQL injection issue through cookie values processed by login.pl and debug.pl that can expose session tokens, password hashes, and stored secret keys. CVE-2026-50110 covers hardcoded credentials for internal services stored in an encoded format that can be reversed to plaintext. CVE-2026-50040 is reflected cross-site scripting through unsanitized content in 404 error pages.

For defense industrial base contractors and other critical infrastructure operators, the Monday work is not theoretical. Inventory StoneFly SC and SCVM deployments, confirm the running version, prioritize any internet-reachable management surfaces, and patch to 8.0.4.29 or later. CISA’s advisory points users with additional questions to StoneFly support, but it does not describe a compensating workaround for organizations that cannot patch immediately.


Published ·Deep Fathom