CVE-2024-30213: Stonefly Scvm

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.

Affected products

  • Stonefly Scvm: before 8.0.4.26 (fixed in 8.0.4.26)

Published 2024-07-12. Last modified 2026-06-17.