CVE-2017-9978: Infoleak
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9978?
CVE-2017-9978 is classified as a medium severity vulnerability due to its potential for account enumeration.
How do I fix CVE-2017-9978?
To remediate CVE-2017-9978, upgrade OSNEXUS QuantaStor to version 4.3.1 or later.
What kind of information does CVE-2017-9978 disclose?
CVE-2017-9978 discloses error messages for non-existent users, allowing attackers to identify valid usernames.
What are the potential impacts of exploiting CVE-2017-9978?
Exploitation of CVE-2017-9978 can lead to account enumeration, increasing the risk of targeted attacks.
Which versions of OSNEXUS QuantaStor are affected by CVE-2017-9978?
CVE-2017-9978 affects OSNEXUS QuantaStor versions prior to 4.3.1.