Database/Control plane, storage & DevOps

Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the management
Impact
Remote code execution on QConvergeConsole, the management application for QLogic/Marvell FastLinQ and Fibre Channel adapters. QConvergeConsole is the tool that flashes adapter firmware and configures boot-from-SAN across a fleet, so code execution there is a route to pushing adapter firmware to every server it manages. One of a cluster of near-identical ZDI-reported issues (CVE-2020-17387, CVE-2020-17388, CVE-2020-15642 through CVE-2020-15645) in the same version.
Who can reach it
Remote attacker with authentication to the QConvergeConsole service — the advisory notes the existing authentication mechanism can be bypassed.
What to do
Upgrade QConvergeConsole past 5.5.0.64. Application upgrade on the management host, no server or switch impact. Better: do not leave a fleet-wide adapter-management console running continuously — stand it up for firmware campaigns and shut it down afterwards, which is a process change that removes a permanently exposed high-value target.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.