OSNEXUS kayıtları
osnexus üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %62,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-269 Improper Privilege Management1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2021-42082İstismar yok | Local Privilege Escalation to root in OSNEXUS QuantaStor before 6.0.0.355osnexus · quantastor · CWE-269 | Yüksek7,8 | — | %0,2 | 10 Tem 2023 |
29İzleyin | CVE-2021-42080İstismar yok | Reflected XSS vulnerability in OSNEXUS QuantaStor before 6.0.0.355osnexus · quantastor · CWE-79 | Yüksek7,4 | — | %0,7 | 10 Tem 2023 |
28İzleyin | CVE-2021-42081İstismar yok | Authenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355osnexus · quantastor · CWE-78 | Yüksek7,2 | — | %1,2 | 10 Tem 2023 |
28İzleyin | CVE-2021-4406İstismar yok | Authenticated Remote COmmand Execution as root in OSNEXUS QuantaStor version 6.0.0.355 and othersosnexus · quantastor · CWE-77 | Yüksek7,2 | — | %1,0 | 10 Tem 2023 |
25İzleyin | CVE-2017-9979Kavram kanıtı | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing osnexus · quantastor · CWE-79 | Orta6,1 | — | %2,6 | 28 Ağu 2017 |
22İzleyin | CVE-2017-9978Kavram kanıtı | On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don'tosnexus · quantastor · CWE-200 | Orta5,3 | — | %4,7 | 28 Ağu 2017 |
21İzleyin | CVE-2021-42083İstismar yok | Authenticated Stored XSS in OSNEXUS QuantaStor 6.0.0.335osnexus · quantastor · CWE-79 | Orta5,4 | — | %0,5 | 10 Tem 2023 |
19İzleyin | CVE-2021-42079İstismar yok | SSRF vulnerability in OSNEXUS QuantaStor before 6.0.0.355osnexus · quantastor · CWE-918 | Orta4,9 | — | %0,7 | 10 Tem 2023 |
- CVE-2021-4208231İzleyin
Local Privilege Escalation to root in OSNEXUS QuantaStor before 6.0.0.355
YüksekCVSS 7,8İstismar yokEPSS %0osnexus · quantastor10 Tem 2023
- CVE-2021-4208029İzleyin
Reflected XSS vulnerability in OSNEXUS QuantaStor before 6.0.0.355
YüksekCVSS 7,4İstismar yokEPSS %1osnexus · quantastor10 Tem 2023
- CVE-2021-4208128İzleyin
Authenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355
YüksekCVSS 7,2İstismar yokEPSS %1osnexus · quantastor10 Tem 2023
- CVE-2021-440628İzleyin
Authenticated Remote COmmand Execution as root in OSNEXUS QuantaStor version 6.0.0.355 and others
YüksekCVSS 7,2İstismar yokEPSS %1osnexus · quantastor10 Tem 2023
- CVE-2017-997925İzleyin
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing
OrtaCVSS 6,1Kavram kanıtıEPSS %3osnexus · quantastor28 Ağu 2017
- CVE-2017-997822İzleyin
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't
OrtaCVSS 5,3Kavram kanıtıEPSS %5osnexus · quantastor28 Ağu 2017
- CVE-2021-4208321İzleyin
Authenticated Stored XSS in OSNEXUS QuantaStor 6.0.0.335
OrtaCVSS 5,4İstismar yokEPSS %1osnexus · quantastor10 Tem 2023
- CVE-2021-4207919İzleyin
SSRF vulnerability in OSNEXUS QuantaStor before 6.0.0.355
OrtaCVSS 4,9İstismar yokEPSS %1osnexus · quantastor10 Tem 2023