CVE-2017-9978
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.
En la aplicación virtual OSNEXUS QuantaStor v4 en versiones anteriores a la 4.3.1, se ha encontrado un error por el cual se envía como respuesta un mensaje de error a usuarios que no existen en el sistema. Un atacante podría aprovechar esta información para ajustar y enumerar cuentas válidas en el sistema buscando nombres de usuario comunes.
OSNEXUS QuantaStor version 4 suffers from multiple information disclosure vulnerabilities including user enumeration.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-06-26 CVE Reserved
- 2017-08-14 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-01-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Osnexus Search vendor "Osnexus" | Quantastor Search vendor "Osnexus" for product "Quantastor" | <= 4.3.0 Search vendor "Osnexus" for product "Quantastor" and version " <= 4.3.0" | - |
Affected
|