CVE-2024-31947: Stonefly Storage Concentrator

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information.

Affected products

  • Stonefly Storage Concentrator: before 8.0.4.26 (fixed in 8.0.4.26)

Published 2024-07-12. Last modified 2026-06-17.