Impact
OSNEXUS QuantaStor is affected by a missing authentication flaw in its Kapacitor configuration that permits remote attackers to run arbitrary code with root privileges. The weakness allows an attacker to bypass all authentication checks and immediately execute commands on the underlying system, potentially compromising confidentiality, integrity, and availability of the host and any services running on it.
Affected Systems
This vulnerability applies to installations of OSNEXUS QuantaStor. No specific affected product versions are listed in the current advisory, so all deployed instances of QuantaStor are potentially vulnerable until a patch is applied or other mitigations are enforced.
Risk and Exploitability
The risk is high, reflected by a CVSS score of 9.8. The EPSS score indicates a 1% probability of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is purely remote and requires no authentication; once access is achieved, an attacker can execute code as root. Based on the lack of authentication controls and the severity rating, the likelihood of exploitation remains significant in environments where the vulnerable interfaces are exposed to untrusted networks.
OpenCVE Enrichment