CVE-2023-51947

CRITICAL

actiNAS SL 2U-8 RDX 3.2.03-SP1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.

Scores

CVSS v3 9.1
EPSS 0.0034
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
actidata/actinas_sl_2u-8_rdx_firmware 3.2.03 sp1
Published Jan 19, 2024
Tracked Since Feb 18, 2026