Record summary

CVE-2017-9978 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.

Description

On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBQuantaStor Software Defined Storage < 4.3.1 - Multiple VulnerabilitiesExploitDB exploitby VVVSecurityNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

5