On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.vvvsecurity.com/advisories/vvvsecurity-advisory-2017-6943.txt | url repurposed exploit third party advisory |
https://www.exploit-db.com/exploits/42517/ | exploit vdb entry third party advisory |
http://seclists.org/fulldisclosure/2017/Aug/23 | mailing list exploit third party advisory |
http://packetstormsecurity.com/files/143780/OSNEXUS-QuantaStor-4-Information-Disclosure.html | exploit vdb entry third party advisory |