CVE-2026-56413
Deferred Deferred - Pending Action

Command Injection in Storage Concentrator SC & SCVM

Vulnerability report for CVE-2026-56413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-30

Last updated on: 2026-07-01

Assigner: ICS-CERT

Description

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-30
Last Modified
2026-07-01
Generated
2026-07-21
AI Q&A
2026-07-01
EPSS Evaluated
2026-07-19
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the Storage Concentrator (SC & SCVM) within the ms_service.pl service, which listens on TCP port 9000 by default. It is a command injection vulnerability where the service accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload. Because the payload is processed without adequate sanitization, this leads to arbitrary command execution with root-level privileges.

Impact Analysis

The impact of this vulnerability is severe. An attacker can remotely execute arbitrary commands on the affected system with root-level privileges without any authentication. This can lead to full system compromise, unauthorized access to sensitive data, disruption of services, and potential use of the system as a foothold for further attacks.

Compliance Impact

This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands with root-level privileges on the affected system. Such a compromise can lead to unauthorized access, data breaches, and loss of system integrity.

Given the severity and nature of this vulnerability, it can negatively impact compliance with common standards and regulations such as GDPR and HIPAA, which require protection of sensitive data and secure system access controls.

Failure to address this vulnerability could result in violations of these regulations due to potential unauthorized data access or system control.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart