GPU VulnDB

Database/Control plane, storage & DevOps

Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same console

CVE-2020-15639Control plane, storage & DevOpsCVE-2020-15640CVE-2020-15641CVE-2020-15642CVE-2020-15643CVE-2020-15644CVE-2020-15645CVE-2020-17387CVE-2020-17388CVE-2020-17389CVE-2020-5803CVE-2020-5804CVE-2020-5805curated

Impact

The earlier cluster on the same console: unauthenticated RCE via decryptFile, unauthenticated file disclosure via getFileUploadBytes, several RCE paths whose authentication requirement is defeated by a bypass in the console's own auth mechanism, path traversal that deletes arbitrary files as SYSTEM or root, and Tomcat credentials stored in cleartext in tomcat-users.xml. Included here because operators routinely find 5.5.0.6x/7x consoles still running on legacy management servers that were never inventoried - the same fleet-wide HBA firmware control as the 2025 cluster, on hosts nobody is patching.

Who can reach it

Any host reachable to the QConvergeConsole web port. Unauthenticated for the RCE and disclosure primitives; the cleartext tomcat-users.xml additionally gives any local OS user on the console host a working login.

What to do

Do not patch this generation - retire it. Inventory for QConvergeConsole installs by port and by package, uninstall from all hosts, and replace with CLI-driven HBA management. If a console must stay, upgrade to the current release, rotate the Tomcat credentials and put the port behind an admin-only ACL. No HBA firmware flash and no storage downtime is required to remove the console.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.