CVE-2017-9978 is an information disclosure vulnerability affecting OSNEXUS QuantaStor virtual appliances prior to version 4.3.1. The flaw allows an unauthenticated attacker to enumerate valid user accounts by analyzing error messages returned for non-existent users. With a CVSS score of 5.3 (Medium), this vulnerability has a low attack complexity and does not require user interaction, but its impact is limited to information disclosure (CWE-200). While not actively exploited in the wild and lacking Metasploit or Nuclei modules, a proof-of-concept exploit is available on ExploitDB, though it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3.0CPE matchmatch criteria | cpe:2.3:a:osnexus:quantastor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.