CISA warns of StoneFly storage flaws that grant root access

CISA has published an advisory for industrial control systems covering multiple vulnerabilities in StoneFly Storage Concentrator and Storage Concentrator Virtual Machine. According to CISA, successful exploitation could allow broad unauthorised access, arbitrary command execution with root privileges, theft of sensitive data, and actions performed as legitimate users across interconnected systems.

What this means for your organisation

Storage systems rarely top the list when security work is prioritised, yet they hold precisely the data an organisation cannot afford to lose or leak. Root on the storage effectively means access to everything on it, backups included. For organisations running industrial or critical infrastructure this scenario hits both confidentiality and the ability to restore operations.

Berigo recommends

  • Determine whether your organisation runs StoneFly devices, including in production and industrial networks.
  • Follow CISA's advisory for versions and mitigations, prioritising devices whose management interface is reachable from the network.
  • Segment storage and management networks from the general office network.
  • Verify that backups exist outside the affected systems and have been tested for restoration.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch