GPU VulnDB

Database/Control plane, storage & DevOps

Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the management

CVE-2020-17389Control plane, storage & DevOpsZDI QConvergeConsolecurated

Impact

Remote code execution on QConvergeConsole, the management application for QLogic/Marvell FastLinQ and Fibre Channel adapters. QConvergeConsole is the tool that flashes adapter firmware and configures boot-from-SAN across a fleet, so code execution there is a route to pushing adapter firmware to every server it manages. One of a cluster of near-identical ZDI-reported issues (CVE-2020-17387, CVE-2020-17388, CVE-2020-15642 through CVE-2020-15645) in the same version.

Who can reach it

Remote attacker with authentication to the QConvergeConsole service — the advisory notes the existing authentication mechanism can be bypassed.

What to do

Upgrade QConvergeConsole past 5.5.0.64. Application upgrade on the management host, no server or switch impact. Better: do not leave a fleet-wide adapter-management console running continuously — stand it up for firmware campaigns and shut it down afterwards, which is a process change that removes a permanently exposed high-value target.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.