Record summary

CVE-2018-12300 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMSeagate NAS OS 4.3.15.1 - Open RedirectCVSS 6.1

Seagate NAS OS 4.3.15.1 contains an open redirect vulnerability in echo-server.html, which can allow an attacker to disclose information in the referer header via the state URL parameter.

Impact

Successful exploitation of this vulnerability could lead to user redirection to malicious websites, potentially resulting in the theft of sensitive information or the installation of malware.

Remediation

Apply the latest security patches or updates provided by Seagate to fix the open redirect vulnerability in NAS OS 4.3.15.1.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscve2018cveredirectseagatenasosvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:seagate:nas_os:4.3.15.1:*:*:*:*:*:*:*
Shodan: http.title:"seagate nas - seagate"
FOFA: title="seagate nas - seagate"
Google: intitle:"seagate nas - seagate"

Source: ProjectDiscovery

References

2