Database/Control plane, storage & DevOps

Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same console
Impact
The earlier cluster on the same console: unauthenticated RCE via decryptFile, unauthenticated file disclosure via getFileUploadBytes, several RCE paths whose authentication requirement is defeated by a bypass in the console's own auth mechanism, path traversal that deletes arbitrary files as SYSTEM or root, and Tomcat credentials stored in cleartext in tomcat-users.xml. Included here because operators routinely find 5.5.0.6x/7x consoles still running on legacy management servers that were never inventoried - the same fleet-wide HBA firmware control as the 2025 cluster, on hosts nobody is patching.
Who can reach it
Any host reachable to the QConvergeConsole web port. Unauthenticated for the RCE and disclosure primitives; the cleartext tomcat-users.xml additionally gives any local OS user on the console host a working login.
What to do
Do not patch this generation - retire it. Inventory for QConvergeConsole installs by port and by package, uninstall from all hosts, and replace with CLI-driven HBA management. If a console must stay, upgrade to the current release, rotate the Tomcat credentials and put the port behind an admin-only ACL. No HBA firmware flash and no storage downtime is required to remove the console.
References
Related entries
- Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem duringCVE-2020-36770 · Slurm (Gentoo ebuild pkg_postinst)Critical
- Cisco Nexus 3000/9000 (internal file management service): Unauthenticated remote file write, read and delete as rootCVE-2021-1361 · Cisco Nexus 3000/9000 (internal file management service)Critical
- GitLab: unauthenticated SSRF through webhooks reaches the internal networkCVE-2021-22175 · GitLab (webhook request handling)Critical
- Brocade Fabric OS (hard-coded credentials): Documented hard-coded credentials in Brocade Fabric OSCVE-2021-27797 · Brocade Fabric OS (hard-coded credentials)Critical
- etcd: Authentication flaw via the debug functionCVE-2021-28235 · etcdCritical
- Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllers: A cluster of critical flawsCVE-2021-31884 · Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllersCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.