Record summary

CVE-2018-12296 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 3, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHSeagate NAS OS 4.3.15.1 - Server Information DisclosureCVSS 7.5

Seagate NAS OS version 4.3.15.1 has insufficient access control which allows attackers to obtain information about the NAS without authentication via empty POST requests in /api/external/7.0/system.System.get_infos.

Impact

An attacker can gain sensitive information about the server, potentially leading to further attacks.

Remediation

Upgrade to a patched version of Seagate NAS OS.

WeaknessesCWE-732
Authorsprincechaddha
Template tagscvecve2018seagatenasosdisclosureunauthvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:seagate:nas_os:4.3.15.1:*:*:*:*:*:*:*
Shodan: http.title:"seagate nas - seagate"
FOFA: title="seagate nas - seagate"
Google: intitle:"seagate nas - seagate"

Source: ProjectDiscovery

References

2