Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-56413: Storage Concentrator (SC & SCVM) allows malicious commands via network packets
CVE-2026-56413
Summary
An attacker can send malicious data to Storage Concentrator (SC & SCVM) via the network, allowing them to execute any command on the system with full control. This is a significant risk because an attacker can take control of the system and access sensitive information. To mitigate this risk, update your Storage Concentrator software to the latest version and ensure that all network traffic is properly secured.
Original title
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform dev...
Original description
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges.
nvd CVSS3.1
10.0
nvd CVSS4.0
10.0
Vulnerability type
CWE-78
OS Command Injection
Published: 30 Jun 2026 · Updated: 23 Jul 2026 · First seen: 1 Jul 2026