Tenable Vulnerabilities and Affected Products
Vulnerabilities associated with ASUSTOR Data Master.
Products
Clear product- Nessus20 vulnerabilities
- Security Center10 vulnerabilities
- Nessus Agent7 vulnerabilities
- Alcatel Lucent I-240W-Q GPON ONT6 vulnerabilities
- ASUSTOR Data Master6 vulnerabilities
- Agent4 vulnerabilities
- Nessus Network Monitor4 vulnerabilities
- nessus_agent4 vulnerabilities
- Tenable Identity Exposure4 vulnerabilities
- Tenable Nessus4 vulnerabilities
- LabKey Server Community Edition3 vulnerabilities
- nessus_network_monitor3 vulnerabilities
- SecurityCenter3 vulnerabilities
- Terrascan3 vulnerabilities
- Network Monitor2 vulnerabilities
- security_center2 vulnerabilities
- Burp Suite Community Edition1 vulnerability
- Check_MK1 vulnerability
- Grandstream GWN70001 vulnerability
- identity_exposure1 vulnerability
- integration-jira-cloud1 vulnerability
- libjpeg-turbo1 vulnerability
- MikroTik RouterOS1 vulnerability
- Tenable Appliance1 vulnerability
- Tenable Identity Exposure Secure Relay1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-15698MEDIUM | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi. CWE-200Aug 27, 2018 | CVSS6.5v3.0 | EPSS1.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15699MEDIUM | ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field. CWE-79Aug 27, 2018 | CVSS6.1v3.0 | EPSS0.646% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15696MEDIUM | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi. CWE-200Aug 27, 2018 | CVSS4.3v3.0 | EPSS0.729% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15695MEDIUM | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi. CWE-22Aug 27, 2018 | CVSS6.5v3.0 | EPSS1.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15697MEDIUM | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history. CWE-200Aug 27, 2018 | CVSS6.5v3.0 | EPSS0.907% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15694HIGH | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled. CWE-22Aug 27, 2018 | CVSS7.5v3.0 | EPSS1.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |