CVE-2018-12296
seagate nas_os Incorrect Permission Assignment for Critical Resource
Record summary
CVE-2018-12296 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 3, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
nas_osBrowse seagate / nas_os | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHSeagate NAS OS 4.3.15.1 - Server Information DisclosureCVSS 7.5
Seagate NAS OS version 4.3.15.1 has insufficient access control which allows attackers to obtain information about the NAS without authentication via empty POST requests in /api/external/7.0/system.System.get_infos.
Impact
An attacker can gain sensitive information about the server, potentially leading to further attacks.
Remediation
Upgrade to a patched version of Seagate NAS OS.
Source: ProjectDiscovery