VendorsOSNEXUSquantastorall versions
Vulnerabilities

OSNEXUS QuantaStor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-42081
Authenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355
Published 2023-07-10 · Modified
9.1EPSS 0.012
CVE-2021-4406
Authenticated Remote COmmand Execution as root in OSNEXUS QuantaStor version 6.0.0.355 and others
Published 2023-07-10 · Modified
9.1EPSS 0.010
CVE-2021-42083
Authenticated Stored XSS in OSNEXUS QuantaStor 6.0.0.335
Published 2023-07-10 · Modified
8.7EPSS 0.005
CVE-2021-42082
Local Privilege Escalation to root in OSNEXUS QuantaStor before 6.0.0.355
Published 2023-07-10 · Modified
7.8EPSS 0.002
CVE-2021-42080
Reflected XSS vulnerability in OSNEXUS QuantaStor before 6.0.0.355
Published 2023-07-10 · Modified
7.4EPSS 0.007
CVE-2021-42079
SSRF vulnerability in OSNEXUS QuantaStor before 6.0.0.355
Published 2023-07-10 · Modified
6.2EPSS 0.007
CVE-2017-9979
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript code as a parameter, aka XSS.
Published 2017-08-28 · Modified
6.11 PoCEPSS 0.026
CVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.
Published 2017-08-28 · Modified
5.31 PoCEPSS 0.047