Quantastor
Vendor:
First CVE: Aug 28, 2017 · Active for 8 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Quantastor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 28, 2017
8 years ago
Most Recent CVE
Jun 4, 2026
51 days ago
CVE Severity & Scoring
Quantastor9 CVEs
44%
44%
11%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low2 (22.2%)
High3 (33.3%)
None4 (44.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-10880CRITICAL OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowi | Jun 4, 2026 | 9.8 | 39 | NO | NO |
CVE-2017-9979MEDIUM On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. T | Aug 28, 2017 | 6.1 | 30 | NO | YES |
CVE-2017-9978MEDIUM On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could | Aug 28, 2017 | 5.3 | 28 | NO | YES |
CVE-2021-4406HIGH An authenticated attacker is able to create alerts that trigger a stored XSS attack.
POC
* go to the alert manager
* open the ITSM tab
* add a webhook with the URL/se | Jul 10, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-42082HIGH Local users are able to execute scripts under root privileges.
POC
On the local host run the following command:
curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`' | Jul 10, 2023 | 7.8 | 23 | NO | NO |
CVE-2021-42081HIGH An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.
POC
http://<IP_ADDRESS>/qstorapi/storageSystemModify?storageSystem=&newName=qua | Jul 10, 2023 | 7.2 | 22 | NO | NO |
CVE-2021-42080HIGH An attacker is able to launch a Reflected XSS attack using a crafted URL.
POC:
Visit the following URL
https://<IPADDRESS>:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror= | Jul 10, 2023 | 7.4 | 22 | NO | NO |
CVE-2021-42083MEDIUM An authenticated attacker is able to create alerts that trigger a stored XSS attack.
POC
* go to the alert manager
* open the ITSM tab
* add a webhook with the URL/se | Jul 10, 2023 | 5.4 | 18 | NO | NO |
CVE-2021-42079MEDIUM An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests.
POC
Step 1: Prepare the SSRF with a req | Jul 10, 2023 | 4.9 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Quantastor
Top CWEs
Versions
No cataloged versions.