OSNEXUS QuantaStor 存在缺失身份验证的远程代码执行漏洞。此漏洞允许远程攻击者在受影响的 OSNEXUS QuantaStor 安装中执行任意代码。利用此漏洞无需进行身份验证。 该特定缺陷存在于 Kapacitor 的配置中。问题是由于在允许访问相关功能之前缺乏身份验证机制。攻击者可以利用此漏洞,以 root 用户的上下文执行代码。此为 ZDI-CAN-30036。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OSNEXUS | QuantaStor | 6.7.3.010+9c965a6414 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OSNEXUS | QuantaStor | 6.7.3.010+9c965a6414 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet