Database/Control plane, storage & DevOps

Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the management
Impact
Remote code execution on QConvergeConsole, the management application for QLogic/Marvell FastLinQ and Fibre Channel adapters. QConvergeConsole is the tool that flashes adapter firmware and configures boot-from-SAN across a fleet, so code execution there is a route to pushing adapter firmware to every server it manages. One of a cluster of near-identical ZDI-reported issues (CVE-2020-17387, CVE-2020-17388, CVE-2020-15642 through CVE-2020-15645) in the same version.
Who can reach it
Remote attacker with authentication to the QConvergeConsole service — the advisory notes the existing authentication mechanism can be bypassed.
What to do
Upgrade QConvergeConsole past 5.5.0.64. Application upgrade on the management host, no server or switch impact. Better: do not leave a fleet-wide adapter-management console running continuously — stand it up for firmware campaigns and shut it down afterwards, which is a process change that removes a permanently exposed high-value target.
References
Related entries
- Ceph CephX authentication protocol: CephX does not correctly bind client identity, so an attacker who can captureCVE-2020-25660 · Ceph CephX authentication protocolHigh
- APC PowerChute Business Edition (v9.0.x and earlier): PowerChute runs the shutdown script that fires when a UPS reportsCVE-2020-7526 · APC PowerChute Business Edition (v9.0.x and earlier)High
- Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1: Authenticated file uploadCVE-2020-7569 · Schneider Electric EcoStruxure Building Operation WebReports / WebStation V1.9-V3.1High
- Nagios XI: OS command injection in the windowswmi config wizard (authenticated)CVE-2021-25296 · Nagios XIHigh
- Nagios XI: OS command injection in the switch config wizardCVE-2021-25297 · Nagios XIHigh
- Nagios XI: OS command injection in the cloud-vm config wizardCVE-2021-25298 · Nagios XIHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.