< securityroom

QSAN Responds to CVE-1999-0519: CIFS Null Session

April  14 , 2025

Abstract

A NETBIOS/SMB share configured with a default, null, or missing password may allow an unauthenticated remote user to establish a CIFS null session against an affected QSAN operating system and enumerate share information.

This issue has been addressed in the releases listed below, in which SMB signing can be enabled from the user interface.

Applied to

Product Severity Fixed Release Availability
QSM Important 4.1.5 and later
XEVO Important Corresponding release paired with QSM 4.1.5 and later

Mitigation

Upgrade the firmware to the latest version. If you need immediate assistance, please contact QSAN technical support via https://www.qsan.com/en/technical_support.

Detail

CVE-1999-0519

Severity: Important

CVSS2 Base Score: 7.5

CVSS2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

A NETBIOS/SMB share password is the default, null, or missing.

Reference

CVE-1999-0519