Known Vulnerabilities for QuantaStor by Osnexus
Listed below are 8 of the newest known vulnerabilities associated with "QuantaStor" by "Osnexus".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-10880 json | OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanit... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2021-42083 json | An authenticated attacker is able to create alerts that trigger a stored XSS attack. | 5.4 - MEDIUM | 2023-07-10 | 2024-01-02 |
| CVE-2021-42082 json | Local users are able to execute scripts under root privileges. | 7.8 - HIGH | 2023-07-10 | 2023-07-14 |
| CVE-2021-42081 json | An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. | 7.2 - HIGH | 2023-07-10 | 2023-07-17 |
| CVE-2021-42080 json | An attacker is able to launch a Reflected XSS attack using a crafted URL. | 6.1 - MEDIUM | 2023-07-10 | 2023-07-14 |
| CVE-2021-42079 json | An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with P... | 4.9 - MEDIUM | 2023-07-10 | 2023-07-14 |
| CVE-2021-4406 json | An administrator is able to execute commands as root via the alerts management dialog | 7.2 - HIGH | 2023-07-10 | 2023-07-13 |
| CVE-2017-9979 json | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be trigge... | 6.1 - MEDIUM | 2017-08-28 | 2017-09-08 |
| CVE-2017-9978 json | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for u... | 5.3 - MEDIUM | 2017-08-28 | 2017-09-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Osnexus | Quantastor | 4.3.0 |